PT-2005-3595 · Iss · Iss Blackice+4
Publicado
2005-12-31
·
Atualizado
2017-07-11
·
CVE-2005-2711
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ISS BlackIce version 3.6
ISS BlackICE PC Protection version 3.6
ISS Server Protection version 3.6
ISS Agent for Server version 3.6
ISS RealSecure Desktop versions 3.6 and 7.0
Description
The issue allows local users to execute arbitrary programs as SYSTEM due to the failure to drop privileges before launching help from the "More Info" button in the "Application Protection" dialog.
Recommendations
For ISS BlackIce version 3.6, consider restricting access to the "More Info" button in the "Application Protection" dialog until a fix is available.
For ISS BlackICE PC Protection version 3.6, restrict the execution of arbitrary programs as SYSTEM by implementing proper privilege dropping mechanisms.
For ISS Server Protection version 3.6, implement a fix to drop privileges before launching help from the "More Info" button.
For ISS Agent for Server version 3.6, apply a patch or configuration change to ensure proper privilege handling.
For ISS RealSecure Desktop versions 3.6 and 7.0, update the application to properly drop privileges before executing help functions.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Iss Agent For Server
Blackice Pc Protection
Iss Blackice
Realsecure Desktop
Iss Server Protection