{"api_version":"1","generated_at":"2026-07-23T09:36:09+00:00","cve":"CVE-2004-1624","urls":{"html":"https://cve.report/CVE-2004-1624","api":"https://cve.report/api/cve/CVE-2004-1624.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-1624","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-1624"},"summary":{"title":"CVE-2004-1624","description":"Carbon Copy 6.0.5257 does not drop system privileges when opening external programs through the help topic interface, which allows local users to gain privileges via (1) the help topic interface in CCW32.exe, which launches Notepad, or (2) the help button in the Carbon Copy Scheduler (CCSched.exe).","state":"PUBLISHED","assigner":"mitre","published_at":"2004-10-21 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.2","severity":"","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://marc.info/?l=bugtraq&m=109846296406459&w=2","name":"http://marc.info/?l=bugtraq&m=109846296406459&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'[Fwd: Altiris Carbon Copy Remote Control  local SYSTEM exploitation.]' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/11500","name":"http://www.securityfocus.com/bid/11500","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Altiris Carbon Copy Remote Control System Local Privilege Escalation Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/12962","name":"http://secunia.com/advisories/12962","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - Altiris Carbon Copy Solution Privilege Escalation Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17838","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17838","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-1624","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-1624","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"1624","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"altiris","cpe5":"carbon_copy","cpe6":"5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"1624","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"altiris","cpe5":"carbon_copy","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T01:00:36.291Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20041022 [Fwd: Altiris Carbon Copy Remote Control  local SYSTEM exploitation.]","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=109846296406459&w=2"},{"name":"11500","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/11500"},{"name":"carboncopy-help-gain-privileges(17838)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17838"},{"name":"12962","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/12962"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-10-22T00:00:00.000Z","descriptions":[{"lang":"en","value":"Carbon Copy 6.0.5257 does not drop system privileges when opening external programs through the help topic interface, which allows local users to gain privileges via (1) the help topic interface in CCW32.exe, which launches Notepad, or (2) the help button in the Carbon Copy Scheduler (CCSched.exe)."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20041022 [Fwd: Altiris Carbon Copy Remote Control  local SYSTEM exploitation.]","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=109846296406459&w=2"},{"name":"11500","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/11500"},{"name":"carboncopy-help-gain-privileges(17838)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17838"},{"name":"12962","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/12962"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-1624","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Carbon Copy 6.0.5257 does not drop system privileges when opening external programs through the help topic interface, which allows local users to gain privileges via (1) the help topic interface in CCW32.exe, which launches Notepad, or (2) the help button in the Carbon Copy Scheduler (CCSched.exe)."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20041022 [Fwd: Altiris Carbon Copy Remote Control  local SYSTEM exploitation.]","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=109846296406459&w=2"},{"name":"11500","refsource":"BID","url":"http://www.securityfocus.com/bid/11500"},{"name":"carboncopy-help-gain-privileges(17838)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17838"},{"name":"12962","refsource":"SECUNIA","url":"http://secunia.com/advisories/12962"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-1624","datePublished":"2005-02-20T05:00:00.000Z","dateReserved":"2005-02-20T00:00:00.000Z","dateUpdated":"2024-08-08T01:00:36.291Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-10-21 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:altiris:carbon_copy:5.0:*:*:*:*:*:*:*","matchCriteriaId":"374C9F53-18BA-4E0A-BF89-B8145E9B2457"},{"vulnerable":true,"criteria":"cpe:2.3:a:altiris:carbon_copy:6.0:*:*:*:*:*:*:*","matchCriteriaId":"FFD35FA6-CB7F-401F-B6BE-AEC9B3710C1A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"1624","Ordinal":"1","Title":"CVE-2004-1624","CVE":"CVE-2004-1624","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"1624","Ordinal":"1","NoteData":"Carbon Copy 6.0.5257 does not drop system privileges when opening external programs through the help topic interface, which allows local users to gain privileges via (1) the help topic interface in CCW32.exe, which launches Notepad, or (2) the help button in the Carbon Copy Scheduler (CCSched.exe).","Type":"Description","Title":"CVE-2004-1624"},{"CveYear":"2004","CveId":"1624","Ordinal":"2","NoteData":"2005-02-20","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"1624","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}