Vulnerabilities > ISS > Blackice PC Protection > 3.6cbr

DATE CVE VULNERABILITY TITLE RISK
2004-12-31 CVE-2004-2126 Unspecified vulnerability in ISS Blackice PC Protection
The upgrade for BlackICE PC Protection 3.6 and earlier sets insecure permissions for .INI files such as (1) blackice.ini, (2) firewall.ini, (3) protect.ini, or (4) sigs.ini, which allows local users to modify BlackICE configuration or possibly execute arbitrary code by exploiting vulnerabilities in the .INI parsers.
local
low complexity
iss
4.6
2004-08-11 CVE-2004-1714 Incorrect Permission Assignment for Critical Resource vulnerability in ISS Blackice PC Protection and Blackice Server Protection
BlackICE PC Protection and Server Protection installs (1) firewall.ini, (2) blackice.ini, (3) sigs.ini and (4) protect.ini with Everyone Full Control permissions, which allows local users to cause a denial of service (crash) or modify configuration, as demonstrated by modifying firewall.ini to contain a large firewall rule.
local
low complexity
iss CWE-732
7.1