PT-2007-1407 · Iss · Blackice Pc Protection

Published

2007-03-06

·

Updated

2018-10-16

·

CVE-2006-7129

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions ISS BlackICE PC Protection versions 3.6 and possibly earlier
Description The issue allows local users to bypass the protection scheme. This is achieved by using the ZwDeleteFile API function to delete the critical file filelock.txt, which stores information about protected files.
Recommendations For ISS BlackICE PC Protection version 3.6 and possibly earlier, consider restricting access to the ZwDeleteFile API function to prevent deletion of the filelock.txt file until a patch is available. As a temporary workaround, monitor the filelock.txt file for unauthorized modifications.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-7129

Affected Products

Blackice Pc Protection