Search

published date: August 27, 2003

CVE-2003-0641 : WatchGuard ServerLock for Windows...

Description

WatchGuard ServerLock for Windows 2000 before SL 2.0.3 allows local users to load arbitrary modules via the OpenProcess() function, as demonstrated using (1) a DLL injection attack, (2) ZwSetSystemInformation, and (3) API hooking in OpenProcess.

Product(s):

  • WatchGuard ServerLock 2.0.1
  • WatchGuard ServerLock 2.0.2
  • WatchGuard ServerLock 2.0

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-2003-0641, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2003-0641 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?