CVE-2004-1714: High severity iss BlackICE PC Protection vulnerability
BlackICE PC Protection and Server Protection installs (1) firewall.ini, (2) blackice.ini, (3) sigs.ini and (4) protect.ini with Everyone Full Control permissions, which allows local users to cause a denial of service (crash) or modify configuration, as demonstrated by modifying firewall.ini to contain a large firewall rule.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1714?
The severity of CVE-2004-1714 is considered moderate due to the potential for local users to crash the system or modify critical configuration files.
How do I fix CVE-2004-1714?
To fix CVE-2004-1714, modify the permissions of the affected configuration files to restrict access from non-administrative users.
Which software is affected by CVE-2004-1714?
CVE-2004-1714 affects ISS BlackICE PC Protection and Server Protection versions 3.6ccf, 3.6ccb, 3.6ccg, among others.
What type of vulnerability is CVE-2004-1714?
CVE-2004-1714 is a local security vulnerability that allows unauthorized modification and potential denial of service.
Can CVE-2004-1714 be exploited remotely?
CVE-2004-1714 cannot be exploited remotely as it requires local access by a user to the affected system.