Vulnerability Name: | CVE-2006-7129 (CCN-29575) | ||||||||
Assigned: | 2006-10-15 | ||||||||
Published: | 2006-10-15 | ||||||||
Updated: | 2018-10-16 | ||||||||
Summary: | ISS BlackICE PC Protection 3.6 cpj and cpu, and possibly earlier versions, allows local users to bypass the protection scheme by using the ZwDeleteFile API function to delete the critical filelock.txt file, which stores information about protected files. | ||||||||
CVSS v3 Severity: | 5.1 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N)
| ||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N) 1.7 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:UR)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:H/Au:N/C:N/I:C/A:N/E:U/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: CCN Type: Full-Disclosure Mailing List, Sun Oct 15 2006 - 11:42:41 CDT ISS BlackICE PC Protection Filelock protection bypass Vulnerability Source: FULLDISC Type: UNKNOWN 20061015 ISS BlackICE PC Protection Filelock protection bypass Vulnerability Source: MITRE Type: CNA CVE-2006-7129 Source: SREASON Type: UNKNOWN 2361 Source: CCN Type: Matousec Advisory 2006-10-15.01 BlackICE Filelock protection bypass Vulnerability Source: MISC Type: UNKNOWN http://www.matousec.com/info/advisories/BlackICE-Filelock-protection-bypass.php Source: OSVDB Type: UNKNOWN 30901 Source: CCN Type: OSVDB ID: 30901 BlackICE ZwDeleteFile API Function filelock.txt Deletion Source: BUGTRAQ Type: UNKNOWN 20061015 ISS BlackICE PC Protection Filelock protection bypass Vulnerability Source: BID Type: UNKNOWN 20546 Source: CCN Type: BID-20546 Internet Security Systems ZWDeleteFile Function Arbitrary File Deletion Vulnerability Source: XF Type: UNKNOWN blackice-filelock-protection-bypass(29575) Source: XF Type: UNKNOWN blackice-filelock-protection-bypass(29575) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |