{"api_version":"1","generated_at":"2026-04-23T01:11:58+00:00","cve":"CVE-2004-2554","urls":{"html":"https://cve.report/CVE-2004-2554","api":"https://cve.report/api/cve/CVE-2004-2554.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-2554","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-2554"},"summary":{"title":"CVE-2004-2554","description":"Novell Client Firewall (NCF) 2.0, as based on the Agnitum Outpost Firewall, allows local users to execute arbitrary code with SYSTEM privileges by opening the NCF tray icon and using the Help functionality to launch programs with SYSTEM privileges.","state":"PUBLISHED","assigner":"mitre","published_at":"2004-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.2","severity":"","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.ciac.org/ciac/bulletins/o-090.shtml","name":"http://www.ciac.org/ciac/bulletins/o-090.shtml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"O-090: Vulnerability in Novell Client Firewall Tray Icon","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://secunia.com/advisories/11014","name":"http://secunia.com/advisories/11014","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - Novell Client Firewall Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1008755","name":"http://securitytracker.com/id?1008755","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Agnitum Outpost Firewall Tray Icon Lets Local Users Execute Commands With SYSTEM Privileges - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/4120","name":"http://www.osvdb.org/4120","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://support.novell.com/cgi-bin/search/searchtid.cgi?/10090585.htm","name":"http://support.novell.com/cgi-bin/search/searchtid.cgi?/10090585.htm","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"TID-10090585 Novell Client Firewall Tray Icon Lets Local Users Execute Commands With SYSTEM ( 01MAR2004)","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/9441","name":"http://www.securityfocus.com/bid/9441","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Agnitum Outpost Firewall Local Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15367","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15367","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-2554","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-2554","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"2554","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"novell","cpe5":"client_firewall","cpe6":"2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T01:29:14.065Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"O-090","tags":["third-party-advisory","government-resource","x_refsource_CIAC","x_transferred"],"url":"http://www.ciac.org/ciac/bulletins/o-090.shtml"},{"name":"1008755","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1008755"},{"name":"ncf-tray-icon-gain-privileges(15367)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15367"},{"name":"11014","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/11014"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.novell.com/cgi-bin/search/searchtid.cgi?/10090585.htm"},{"name":"4120","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/4120"},{"name":"9441","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/9441"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-03-01T00:00:00.000Z","descriptions":[{"lang":"en","value":"Novell Client Firewall (NCF) 2.0, as based on the Agnitum Outpost Firewall, allows local users to execute arbitrary code with SYSTEM privileges by opening the NCF tray icon and using the Help functionality to launch programs with SYSTEM privileges."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"O-090","tags":["third-party-advisory","government-resource","x_refsource_CIAC"],"url":"http://www.ciac.org/ciac/bulletins/o-090.shtml"},{"name":"1008755","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1008755"},{"name":"ncf-tray-icon-gain-privileges(15367)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15367"},{"name":"11014","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/11014"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.novell.com/cgi-bin/search/searchtid.cgi?/10090585.htm"},{"name":"4120","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/4120"},{"name":"9441","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/9441"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-2554","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Novell Client Firewall (NCF) 2.0, as based on the Agnitum Outpost Firewall, allows local users to execute arbitrary code with SYSTEM privileges by opening the NCF tray icon and using the Help functionality to launch programs with SYSTEM privileges."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"O-090","refsource":"CIAC","url":"http://www.ciac.org/ciac/bulletins/o-090.shtml"},{"name":"1008755","refsource":"SECTRACK","url":"http://securitytracker.com/id?1008755"},{"name":"ncf-tray-icon-gain-privileges(15367)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15367"},{"name":"11014","refsource":"SECUNIA","url":"http://secunia.com/advisories/11014"},{"name":"http://support.novell.com/cgi-bin/search/searchtid.cgi?/10090585.htm","refsource":"CONFIRM","url":"http://support.novell.com/cgi-bin/search/searchtid.cgi?/10090585.htm"},{"name":"4120","refsource":"OSVDB","url":"http://www.osvdb.org/4120"},{"name":"9441","refsource":"BID","url":"http://www.securityfocus.com/bid/9441"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-2554","datePublished":"2005-11-21T11:00:00.000Z","dateReserved":"2005-11-21T00:00:00.000Z","dateUpdated":"2024-08-08T01:29:14.065Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:novell:client_firewall:2.0:*:*:*:*:*:*:*","matchCriteriaId":"45A29B4A-377D-4264-ABD1-6A14C9BDBC7D"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"2554","Ordinal":"1","Title":"CVE-2004-2554","CVE":"CVE-2004-2554","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"2554","Ordinal":"1","NoteData":"Novell Client Firewall (NCF) 2.0, as based on the Agnitum Outpost Firewall, allows local users to execute arbitrary code with SYSTEM privileges by opening the NCF tray icon and using the Help functionality to launch programs with SYSTEM privileges.","Type":"Description","Title":"CVE-2004-2554"},{"CveYear":"2004","CveId":"2554","Ordinal":"2","NoteData":"2005-11-21","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"2554","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}