HIGH · 7.2

CVE-2005-2711

ISS BlackIce 3.6, as used in multiple products including BlackICE PC Protection, Server Protection, Agent for Server, and RealSecure Desktop 3.6 and 7.0, does not drop privileges before launching help...

Vulnerability Description

ISS BlackIce 3.6, as used in multiple products including BlackICE PC Protection, Server Protection, Agent for Server, and RealSecure Desktop 3.6 and 7.0, does not drop privileges before launching help from the "More Info" button in the "Application Protection" dialog, which allows local users to execute arbitrary programs as SYSTEM.

CVSS Score

7.2

HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
IssBlackice Agent ServerAll versions
IssBlackice Pc Protection3.6
IssBlackice Server ProtectionAll versions
IssRealsecure Desktop3.6

References

FAQ

What is CVE-2005-2711?

CVE-2005-2711 is a vulnerability with a CVSS score of 7.2 (HIGH). ISS BlackIce 3.6, as used in multiple products including BlackICE PC Protection, Server Protection, Agent for Server, and RealSecure Desktop 3.6 and 7.0, does not drop privileges before launching help...

How severe is CVE-2005-2711?

CVE-2005-2711 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2005-2711?

Check the references section above for vendor advisories and patch information. Affected products include: Iss Blackice Agent Server, Iss Blackice Pc Protection, Iss Blackice Server Protection, Iss Realsecure Desktop.