PT-2007-1407 · Iss · Blackice Pc Protection
Published
2007-03-06
·
Updated
2018-10-16
·
CVE-2006-7129
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
ISS BlackICE PC Protection versions 3.6 and possibly earlier
Description
The issue allows local users to bypass the protection scheme. This is achieved by using the ZwDeleteFile API function to delete the critical file
filelock.txt, which stores information about protected files.Recommendations
For ISS BlackICE PC Protection version 3.6 and possibly earlier, consider restricting access to the ZwDeleteFile API function to prevent deletion of the
filelock.txt file until a patch is available. As a temporary workaround, monitor the filelock.txt file for unauthorized modifications.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Blackice Pc Protection