CVE-2003-0704 describes a local privilege escalation vulnerability in KisMAC versions prior to 0.05d. The software insecurely trusts user-supplied environment variables, specifically $DRIVER_KEXT, when performing chown operations on files and directories. This flaw allows a local attacker to gain elevated privileges by manipulating this variable in several shell scripts. The vulnerability carries a CVSS score of 7.2, indicating high severity. It is a local attack (AV:L) with low attack complexity (AC:L) and requires no authentication (Au:N), leading to complete compromise of confidentiality, integrity, and availability (C:C/I:C/A:C). There is no evidence of active exploitation, and no exploit code is publicly available through Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.05dCPE matchmatch criteria | cpe:2.3:a:kismac:kismac:0.05d:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.