Vulnerabilities > CVE-2006-7129 - Unspecified vulnerability in ISS Blackice PC Protection 3.6Cpj/3.6Cpu

047910
CVSS 2.1 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
local
low complexity
iss
exploit available

Summary

ISS BlackICE PC Protection 3.6 cpj and cpu, and possibly earlier versions, allows local users to bypass the protection scheme by using the ZwDeleteFile API function to delete the critical filelock.txt file, which stores information about protected files.

Vulnerable Configurations

Part Description Count
Application
Iss
2

Exploit-Db

descriptionInternet Security Systems 3.6 ZWDeleteFile Function Arbitrary File Deletion Vulnerability. CVE-2006-7129. Local exploits for multiple platform
idEDB-ID:28817
last seen2016-02-03
modified2006-10-16
published2006-10-16
reporterMatousec Transparent security
sourcehttps://www.exploit-db.com/download/28817/
titleInternet Security Systems 3.6 = ZWDeleteFile Function Arbitrary File Deletion Vulnerability