Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-3999

Опубликовано: 05 авг. 2006
Источник: nvd
CVSS2: 4.6
EPSS Низкий

Описание

ISS BlackICE PC Protection 3.6.cpj, 3.6.cpiE, and possibly earlier versions do not properly monitor the integrity of the pamversion.dll BlackICE library, which allows local users to subvert BlackICE by replacing pamversion.dll. NOTE: in most cases, the attack would not cross privilege boundaries because replacing pamversion.dll requires administrative privileges. However, this issue is a vulnerability because BlackICE is intended to protect against certain rogue privileged actions.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:iss:blackice_pc_protection:3.6cpie:*:*:*:*:*:*:*
cpe:2.3:a:iss:blackice_pc_protection:3.6cpj:*:*:*:*:*:*:*

EPSS

Процентиль: 20%
0.00063
Низкий

4.6 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

ISS BlackICE PC Protection 3.6.cpj, 3.6.cpiE, and possibly earlier versions do not properly monitor the integrity of the pamversion.dll BlackICE library, which allows local users to subvert BlackICE by replacing pamversion.dll. NOTE: in most cases, the attack would not cross privilege boundaries because replacing pamversion.dll requires administrative privileges. However, this issue is a vulnerability because BlackICE is intended to protect against certain rogue privileged actions.

EPSS

Процентиль: 20%
0.00063
Низкий

4.6 Medium

CVSS2

Дефекты

NVD-CWE-Other