CVE-2006-7129 Information

Description

ISS BlackICE PC Protection 3.6 cpj and cpu and possibly earlier versions allows local users to bypass the protection scheme by using the ZwDeleteFile API function to delete the critical filelock.txt file which stores information about protected files.

Reference

http://archives.neohapsis.com/archives/fulldisclosure/2006-10/0298.html http://securityreason.com/securityalert/2361 http://www.matousec.com/info/advisories/BlackICE-Filelock-protection-bypass.php http://www.osvdb.org/30901 http://www.securityfocus.com/archive/1/448763/100/0/threaded http://www.securityfocus.com/bid/20546 https://exchange.xforce.ibmcloud.com/vulnerabilities/29575

Share on: