Back to search
CVE-2004-1714
Published: Feb 26, 2005
Modified: Aug 8, 2024
PUBLISHED
Description
BlackICE PC Protection and Server Protection installs (1) firewall.ini, (2) blackice.ini, (3) sigs.ini and (4) protect.ini with Everyone Full Control permissions, which allows local users to cause a denial of service (crash) or modify configuration, as demonstrated by modifying firewall.ini to contain a large firewall rule.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20040811 ISS BlackIce Server Protect Unprivileged User Attack
mailing-list
x_refsource_FULLDISC
10915
vdb-entry
x_refsource_BID
20040811 BlackICE unprivileged local user attack
mailing-list
x_refsource_BUGTRAQ
blackice-firewall-dos(16959)
vdb-entry
x_refsource_XF
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now