Vulnerabilities > ISS > Blackice PC Protection > 3.6cpu

DATE CVE VULNERABILITY TITLE RISK
2007-03-06 CVE-2006-7129 Unspecified vulnerability in ISS Blackice PC Protection 3.6Cpj/3.6Cpu
ISS BlackICE PC Protection 3.6 cpj and cpu, and possibly earlier versions, allows local users to bypass the protection scheme by using the ZwDeleteFile API function to delete the critical filelock.txt file, which stores information about protected files.
local
low complexity
iss
2.1
2005-12-31 CVE-2005-2711 Local Privilege Escalation vulnerability in Internet Security Systems BlackICE and RealSecure Desktop
ISS BlackIce 3.6, as used in multiple products including BlackICE PC Protection, Server Protection, Agent for Server, and RealSecure Desktop 3.6 and 7.0, does not drop privileges before launching help from the "More Info" button in the "Application Protection" dialog, which allows local users to execute arbitrary programs as SYSTEM.
local
low complexity
iss
7.2