First published: Tue Mar 06 2007(Updated: )
ISS BlackICE PC Protection 3.6 cpj and cpu, and possibly earlier versions, allows local users to bypass the protection scheme by using the ZwDeleteFile API function to delete the critical filelock.txt file, which stores information about protected files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM ISS BlackICE PC Protection | =3.6cpj | |
IBM ISS BlackICE PC Protection | =3.6cpu |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-7129 is classified as a high severity vulnerability due to the potential for local users to bypass critical protection mechanisms.
Fixing CVE-2006-7129 involves upgrading to a later version of ISS BlackICE PC Protection that addresses this vulnerability.
CVE-2006-7129 affects users of ISS BlackICE PC Protection versions 3.6 cpj and 3.6 cpu, and possibly earlier versions.
CVE-2006-7129 allows an attacker with local access to delete the filelock.txt, thereby bypassing the file protection scheme.
Currently, there are no known workarounds for CVE-2006-7129; upgrading to a secure version is necessary to mitigate the risk.