PT-2004-2618 · Unknown · Blackice Server Protection+1

CVE-2004-1714

·

Publicado

2004-08-11

·

Atualizado

2024-01-26

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions BlackICE PC Protection and Server Protection (affected versions not specified)
Description The issue allows local users to cause a denial of service or modify configuration due to the installation of certain files with Everyone Full Control permissions. Specifically, files such as firewall.ini, blackice.ini, sigs.ini, and protect.ini are installed with these permissions. This can be exploited by modifying the firewall.ini file to contain a large firewall rule, demonstrating the potential for a denial of service or configuration modification.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Permission

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2004-1714

Produtos afetados

Blackice Pc Protection
Blackice Server Protection