CVE-2004-2125
Summary
| CVE | CVE-2004-2125 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-12-31 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Buffer overflow in blackd.exe for BlackICE PC Protection 3.6 and other versions before 3.6.ccb, with application protection off, allows local users to gain system privileges by modifying the .INI file to contain a long packetLog.fileprefix value. |
Risk And Classification
Primary CVSS: v2.0 4.6 from [email protected]
AV:L/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Iss | Blackice Agent Server | 3.6eca | All | All | All |
| Application | Iss | Blackice Pc Protection | 3.6cbd | All | All | All |
| Application | Iss | Blackice Server Protection | 3.6cbz | All | All | All |
| Application | Iss | Realsecure Desktop | 3.6eca | All | All | All |
| Application | Iss | Realsecure Desktop | 7.0ebg | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Neohapsis Archives - ISS Discuss - #0157 - [ISSForum] Third party BlackICE advisory | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| marc.info | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Internet Security Systems BlackICE PC Protection blackd.exe Local Buffer Overrun Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Secunia - Advisories - BlackICE PC Protection Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| www.osvdb.org/3740 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.