CVE-2004-1714

BlackICE PC Protection and Server Protection installs (1) firewall.ini, (2) blackice.ini, (3) sigs.ini and (4) protect.ini with Everyone Full Control permissions, which allows local users to cause a denial of service (crash) or modify configuration, as demonstrated by modifying firewall.ini to contain a large firewall rule.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:iss:blackice_pc_protection:3.6cbd:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_pc_protection:3.6cbr:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_pc_protection:3.6cbz:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_pc_protection:3.6cca:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_pc_protection:3.6ccb:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_pc_protection:3.6ccc:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_pc_protection:3.6ccd:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_pc_protection:3.6cce:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_pc_protection:3.6ccf:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_pc_protection:3.6ccg:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_server_protection:3.5cdf:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_server_protection:3.6cbz:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_server_protection:3.6cca:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_server_protection:3.6ccb:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_server_protection:3.6ccc:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_server_protection:3.6ccd:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_server_protection:3.6cce:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_server_protection:3.6ccf:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_server_protection:3.6ccg:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_server_protection:3.6cch:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_server_protection:3.6cno:*:*:*:*:*:*:*

History

20 Nov 2024, 23:51

Type Values Removed Values Added
References () http://lists.grok.org.uk/pipermail/full-disclosure/2004-August/025112.html - Not Applicable () http://lists.grok.org.uk/pipermail/full-disclosure/2004-August/025112.html - Not Applicable
References () http://marc.info/?l=bugtraq&m=109223751031166&w=2 - Mailing List () http://marc.info/?l=bugtraq&m=109223751031166&w=2 - Mailing List
References () http://www.securityfocus.com/bid/10915 - Broken Link, Exploit, Third Party Advisory, VDB Entry, Vendor Advisory () http://www.securityfocus.com/bid/10915 - Broken Link, Exploit, Third Party Advisory, VDB Entry, Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/16959 - Third Party Advisory, VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/16959 - Third Party Advisory, VDB Entry

26 Jan 2024, 17:21

Type Values Removed Values Added
CVSS v2 : 2.1
v3 : unknown
v2 : 2.1
v3 : 7.1
CWE NVD-CWE-Other CWE-732
References (BUGTRAQ) http://marc.info/?l=bugtraq&m=109223751031166&w=2 - (BUGTRAQ) http://marc.info/?l=bugtraq&m=109223751031166&w=2 - Mailing List
References (BID) http://www.securityfocus.com/bid/10915 - Exploit, Vendor Advisory (BID) http://www.securityfocus.com/bid/10915 - Broken Link, Exploit, Third Party Advisory, VDB Entry, Vendor Advisory
References (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/16959 - (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/16959 - Third Party Advisory, VDB Entry
References (FULLDISC) http://lists.grok.org.uk/pipermail/full-disclosure/2004-August/025112.html - Exploit, Patch, Vendor Advisory (FULLDISC) http://lists.grok.org.uk/pipermail/full-disclosure/2004-August/025112.html - Not Applicable

Information

Published : 2004-08-11 04:00

Updated : 2024-11-20 23:51


NVD link : CVE-2004-1714

Mitre link : CVE-2004-1714

CVE.ORG link : CVE-2004-1714


JSON object : View

Products Affected

iss

  • blackice_pc_protection
  • blackice_server_protection
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource