First published: Fri Dec 31 2004(Updated: )
Buffer overflow in blackd.exe for BlackICE PC Protection 3.6 and other versions before 3.6.ccb, with application protection off, allows local users to gain system privileges by modifying the .INI file to contain a long packetLog.fileprefix value.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Iss Realsecure Desktop | =7.0ebg | |
IBM ISS BlackICE PC Protection | =3.6cbd | |
IBM ISS BlackICE Agent Server | =3.6eca | |
ISS BlackICE Server Protection | =3.6cbz | |
Iss Realsecure Desktop | =3.6eca |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2125 is classified as a local privilege escalation vulnerability due to a buffer overflow.
To fix CVE-2004-2125, ensure you update BlackICE PC Protection to version 3.6.ccb or later.
CVE-2004-2125 affects local users of BlackICE PC Protection versions prior to 3.6.ccb.
Attackers can exploit CVE-2004-2125 to gain system privileges on affected systems.
If you are using an affected version of BlackICE PC Protection and application protection is off, your system is vulnerable to CVE-2004-2125.