Vulnerabilities
Vulnerable Software
ISS BlackICE PC Protection 3.6 cpj and cpu, and possibly earlier versions, allows local users to bypass the protection scheme by using the ZwDeleteFile API function to delete the critical filelock.txt file, which stores information about protected files.
CVSS Score
2.1
EPSS Score
0.002
Published
2007-03-06
ISS BlackIce 3.6, as used in multiple products including BlackICE PC Protection, Server Protection, Agent for Server, and RealSecure Desktop 3.6 and 7.0, does not drop privileges before launching help from the "More Info" button in the "Application Protection" dialog, which allows local users to execute arbitrary programs as SYSTEM.
CVSS Score
7.2
EPSS Score
0.001
Published
2005-12-31


Contact Us

Shodan ® - All rights reserved