PT-2004-2618 · Unknown · Blackice Server Protection+1
CVE-2004-1714
·
Publicado
2004-08-11
·
Atualizado
2024-01-26
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
BlackICE PC Protection and Server Protection (affected versions not specified)
Description
The issue allows local users to cause a denial of service or modify configuration due to the installation of certain files with Everyone Full Control permissions. Specifically, files such as
firewall.ini, blackice.ini, sigs.ini, and protect.ini are installed with these permissions. This can be exploited by modifying the firewall.ini file to contain a large firewall rule, demonstrating the potential for a denial of service or configuration modification.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Incorrect Permission
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Blackice Pc Protection
Blackice Server Protection