WatchGuard ServerLock Unauthorized Kernel Module Loading Vulnerability

BID:8222

Info

WatchGuard ServerLock Unauthorized Kernel Module Loading Vulnerability

Bugtraq ID: 8222
Class: Design Error
CVE: CVE-2003-0641
Remote: No
Local: Yes
Published: Jul 17 2003 12:00AM
Updated: Jul 11 2009 10:56PM
Credit: Reported by Jan K. Rutkowski <[email protected]>.
Vulnerable: WatchGuard ServerLock 2.0.2
WatchGuard ServerLock 2.0.1
WatchGuard ServerLock 2.0
Not Vulnerable: WatchGuard ServerLock 2.0.4
WatchGuard ServerLock 2.0.3

Discussion

WatchGuard ServerLock Unauthorized Kernel Module Loading Vulnerability

WatchGuard ServerLock is prone to a vulnerability that may permit a malicious program to inject arbitrary code into trusted runtime processes, potentially allowing an arbitrary module to be loaded into the Windows 2000 kernel via the ZwSetSystemInformation() function. This could be exploited to circumvent the security provided by ServerLock.

This issue is reported to affects Windows 2000 systems.

Exploit / POC

WatchGuard ServerLock Unauthorized Kernel Module Loading Vulnerability

This discoverer of this vulnerability has claimed to have exploited this issue. Exploit code is not reported to be circulating in the wild at the time of writing.

Solution / Fix

WatchGuard ServerLock Unauthorized Kernel Module Loading Vulnerability

Solution:
WatchGuard has addressed this issue in ServerLock version 2.0.3 and later. For information on how to obtain patches, please visit the WatchGuard LiveSecurity website referenced below.

References

WatchGuard ServerLock Unauthorized Kernel Module Loading Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report