{"api_version":"1","generated_at":"2026-07-23T07:30:12+00:00","cve":"CVE-2003-1121","urls":{"html":"https://cve.report/CVE-2003-1121","api":"https://cve.report/api/cve/CVE-2003-1121.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2003-1121","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2003-1121"},"summary":{"title":"CVE-2003-1121","description":"Services in ScriptLogic 4.01, and possibly other versions before 4.14, process client requests at raised privileges, which allows remote attackers to (1) modify arbitrary registry entries via the ScriptLogic RPC service (SLRPC) or (2) modify arbitrary configuration via the RunAdmin services (SLRAserver.exe and SLRAclient.exe).","state":"PUBLISHED","assigner":"mitre","published_at":"2003-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.kb.cert.org/vuls/id/609137","name":"http://www.kb.cert.org/vuls/id/609137","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"CERT/CC Vulnerability Note VU#609137","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/CRDY-5EXQSV","name":"http://www.kb.cert.org/vuls/id/CRDY-5EXQSV","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"ScriptLogic Corporation Information for VU#231705","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/7477","name":"http://www.securityfocus.com/bid/7477","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"ScriptLogic RunAdmin Service Administrative Access Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11921","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11921","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11920","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11920","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/231705","name":"http://www.kb.cert.org/vuls/id/231705","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"CERT/CC Vulnerability Note VU#231705","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/7475","name":"http://www.securityfocus.com/bid/7475","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"ScriptLogic Arbitrary Registry Modification Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.kb.cert.org/vuls/id/CRDY-5EXQRP","name":"http://www.kb.cert.org/vuls/id/CRDY-5EXQRP","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"ScriptLogic Corporation Information for VU#609137","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2003-1121","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2003-1121","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2003","cve_id":"1121","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"scriptlogic","cpe5":"scriptlogic","cpe6":"4.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T02:12:36.131Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"scriptlogic-runadmin-admin-access(11921)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11921"},{"name":"VU#231705","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/231705"},{"name":"7477","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/7477"},{"name":"7475","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/7475"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/CRDY-5EXQRP"},{"name":"scriptlogic-rpc-modify-registry(11920)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11920"},{"name":"VU#609137","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/609137"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/CRDY-5EXQSV"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2003-04-30T00:00:00.000Z","descriptions":[{"lang":"en","value":"Services in ScriptLogic 4.01, and possibly other versions before 4.14, process client requests at raised privileges, which allows remote attackers to (1) modify arbitrary registry entries via the ScriptLogic RPC service (SLRPC) or (2) modify arbitrary configuration via the RunAdmin services (SLRAserver.exe and SLRAclient.exe)."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"scriptlogic-runadmin-admin-access(11921)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11921"},{"name":"VU#231705","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/231705"},{"name":"7477","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/7477"},{"name":"7475","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/7475"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.kb.cert.org/vuls/id/CRDY-5EXQRP"},{"name":"scriptlogic-rpc-modify-registry(11920)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11920"},{"name":"VU#609137","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/609137"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.kb.cert.org/vuls/id/CRDY-5EXQSV"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2003-1121","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Services in ScriptLogic 4.01, and possibly other versions before 4.14, process client requests at raised privileges, which allows remote attackers to (1) modify arbitrary registry entries via the ScriptLogic RPC service (SLRPC) or (2) modify arbitrary configuration via the RunAdmin services (SLRAserver.exe and SLRAclient.exe)."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"scriptlogic-runadmin-admin-access(11921)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11921"},{"name":"VU#231705","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/231705"},{"name":"7477","refsource":"BID","url":"http://www.securityfocus.com/bid/7477"},{"name":"7475","refsource":"BID","url":"http://www.securityfocus.com/bid/7475"},{"name":"http://www.kb.cert.org/vuls/id/CRDY-5EXQRP","refsource":"CONFIRM","url":"http://www.kb.cert.org/vuls/id/CRDY-5EXQRP"},{"name":"scriptlogic-rpc-modify-registry(11920)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11920"},{"name":"VU#609137","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/609137"},{"name":"http://www.kb.cert.org/vuls/id/CRDY-5EXQSV","refsource":"CONFIRM","url":"http://www.kb.cert.org/vuls/id/CRDY-5EXQSV"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2003-1121","datePublished":"2005-03-12T05:00:00.000Z","dateReserved":"2005-03-11T00:00:00.000Z","dateUpdated":"2024-08-08T02:12:36.131Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2003-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:a:scriptlogic:scriptlogic:4.1:*:*:*:*:*:*:*","matchCriteriaId":"D26DE2A1-5011-4D98-BFC6-A77039F36484"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2003","CveId":"1121","Ordinal":"1","Title":"CVE-2003-1121","CVE":"CVE-2003-1121","Year":"2003"},"notes":[{"CveYear":"2003","CveId":"1121","Ordinal":"1","NoteData":"Services in ScriptLogic 4.01, and possibly other versions before 4.14, process client requests at raised privileges, which allows remote attackers to (1) modify arbitrary registry entries via the ScriptLogic RPC service (SLRPC) or (2) modify arbitrary configuration via the RunAdmin services (SLRAserver.exe and SLRAclient.exe).","Type":"Description","Title":"CVE-2003-1121"},{"CveYear":"2003","CveId":"1121","Ordinal":"2","NoteData":"2005-03-12","Type":"Other","Title":"Published"},{"CveYear":"2003","CveId":"1121","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}