CVE Database
/

CVE-2006-3999

Back to search

CVE-2006-3999

Published: Aug 5, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

ISS BlackICE PC Protection 3.6.cpj, 3.6.cpiE, and possibly earlier versions do not properly monitor the integrity of the pamversion.dll BlackICE library, which allows local users to subvert BlackICE by replacing pamversion.dll. NOTE: in most cases, the attack would not cross privilege boundaries because replacing pamversion.dll requires administrative privileges. However, this issue is a vulnerability because BlackICE is intended to protect against certain rogue privileged actions.

VendorProductVersions

n/a

n/a

affected
n/a

References

1016618
vdb-entry
x_refsource_SECTRACK
1338
third-party-advisory
x_refsource_SREASON

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now