Services in ScriptLogic 4.01, and possibly other versions before 4.14, process client requests at raised privileges, which allows remote attackers to (1) modify arbitrary registry entries via the ScriptLogic RPC service (SLRPC) or (2) modify arbitrary configuration via the RunAdmin services (SLRAserver.exe and SLRAclient.exe).
https://exchange.xforce.ibmcloud.com/vulnerabilities/11921
https://exchange.xforce.ibmcloud.com/vulnerabilities/11920
http://www.securityfocus.com/bid/7477
http://www.securityfocus.com/bid/7475
http://www.kb.cert.org/vuls/id/CRDY-5EXQSV
http://www.kb.cert.org/vuls/id/CRDY-5EXQRP