CVE-2005-2711: High severity iss RealSecure Desktop vulnerability
ISS BlackIce 3.6, as used in multiple products including BlackICE PC Protection, Server Protection, Agent for Server, and RealSecure Desktop 3.6 and 7.0, does not drop privileges before launching help from the "More Info" button in the "Application Protection" dialog, which allows local users to execute arbitrary programs as SYSTEM.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-2711?
CVE-2005-2711 has a medium severity rating due to the potential for local privilege escalation.
How do I fix CVE-2005-2711?
To mitigate CVE-2005-2711, apply any patches or updates provided by ISS for the affected versions of their software.
Which products are affected by CVE-2005-2711?
CVE-2005-2711 affects ISS BlackIce 3.6, BlackICE PC Protection 3.6, RealSecure Desktop versions 3.6 and 7.0, and the Blackice Agent for Server.
Can CVE-2005-2711 be exploited remotely?
CVE-2005-2711 cannot be exploited remotely, as it requires local access to the affected system.
What types of attacks are possible with CVE-2005-2711?
CVE-2005-2711 may allow attackers to escalate their privileges on a local machine, potentially leading to unauthorized access or data manipulation.