Lucene search

K
nvd[email protected]NVD:CVE-2005-2711
HistoryDec 31, 2005 - 5:00 a.m.

CVE-2005-2711

2005-12-3105:00:00
web.nvd.nist.gov
3

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.1

Confidence

High

EPSS

0.001

Percentile

25.6%

ISS BlackIce 3.6, as used in multiple products including BlackICE PC Protection, Server Protection, Agent for Server, and RealSecure Desktop 3.6 and 7.0, does not drop privileges before launching help from the “More Info” button in the “Application Protection” dialog, which allows local users to execute arbitrary programs as SYSTEM.

Affected configurations

Nvd
Node
issblackice_agent_server
OR
issblackice_pc_protectionMatch3.6
OR
issblackice_pc_protectionMatch3.6cpu
OR
issblackice_server_protection
OR
issrealsecure_desktopMatch3.6
OR
issrealsecure_desktopMatch7.0
VendorProductVersionCPE
issblackice_agent_server*cpe:2.3:a:iss:blackice_agent_server:*:*:*:*:*:*:*:*
issblackice_pc_protection3.6cpe:2.3:a:iss:blackice_pc_protection:3.6:*:*:*:*:*:*:*
issblackice_pc_protection3.6cpucpe:2.3:a:iss:blackice_pc_protection:3.6cpu:*:*:*:*:*:*:*
issblackice_server_protection*cpe:2.3:a:iss:blackice_server_protection:*:*:*:*:*:*:*:*
issrealsecure_desktop3.6cpe:2.3:a:iss:realsecure_desktop:3.6:*:*:*:*:*:*:*
issrealsecure_desktop7.0cpe:2.3:a:iss:realsecure_desktop:7.0:*:*:*:*:*:*:*

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.1

Confidence

High

EPSS

0.001

Percentile

25.6%

Related for NVD:CVE-2005-2711