{"api_version":"1","generated_at":"2026-05-13T11:01:06+00:00","cve":"CVE-2004-2125","urls":{"html":"https://cve.report/CVE-2004-2125","api":"https://cve.report/api/cve/CVE-2004-2125.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-2125","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-2125"},"summary":{"title":"CVE-2004-2125","description":"Buffer overflow in blackd.exe for BlackICE PC Protection 3.6 and other versions before 3.6.ccb, with application protection off, allows local users to gain system privileges by modifying the .INI file to contain a long packetLog.fileprefix value.","state":"PUBLISHED","assigner":"mitre","published_at":"2004-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.6","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://archives.neohapsis.com/archives/iss/2004-q1/0157.html","name":"http://archives.neohapsis.com/archives/iss/2004-q1/0157.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Neohapsis Archives - ISS Discuss - #0157 - [ISSForum] Third party BlackICE advisory","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=107530966524193&w=2","name":"http://marc.info/?l=bugtraq&m=107530966524193&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/9514","name":"http://www.securityfocus.com/bid/9514","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Internet Security Systems BlackICE PC Protection blackd.exe Local Buffer Overrun Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/10739","name":"http://secunia.com/advisories/10739","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Secunia - Advisories - BlackICE PC Protection Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/3740","name":"http://www.osvdb.org/3740","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/14965","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/14965","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-2125","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-2125","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"2125","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"iss","cpe5":"blackice_agent_server","cpe6":"3.6eca","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"2125","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"iss","cpe5":"blackice_pc_protection","cpe6":"3.6cbd","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"2125","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"iss","cpe5":"blackice_server_protection","cpe6":"3.6cbz","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"2125","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"iss","cpe5":"realsecure_desktop","cpe6":"3.6eca","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"2125","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"iss","cpe5":"realsecure_desktop","cpe6":"7.0ebg","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T01:15:01.601Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"blackice-blackdexe-bo(14965)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/14965"},{"name":"9514","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/9514"},{"name":"3740","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/3740"},{"name":"20040128 SRT2004-01-17-0227 - BlackICE allows local users to become SYSTEM","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=107530966524193&w=2"},{"name":"[ISSForum] 20040128 Third party BlackICE advisory","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://archives.neohapsis.com/archives/iss/2004-q1/0157.html"},{"name":"10739","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/10739"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-01-28T00:00:00.000Z","descriptions":[{"lang":"en","value":"Buffer overflow in blackd.exe for BlackICE PC Protection 3.6 and other versions before 3.6.ccb, with application protection off, allows local users to gain system privileges by modifying the .INI file to contain a long packetLog.fileprefix value."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"blackice-blackdexe-bo(14965)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/14965"},{"name":"9514","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/9514"},{"name":"3740","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/3740"},{"name":"20040128 SRT2004-01-17-0227 - BlackICE allows local users to become SYSTEM","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=107530966524193&w=2"},{"name":"[ISSForum] 20040128 Third party BlackICE advisory","tags":["mailing-list","x_refsource_MLIST"],"url":"http://archives.neohapsis.com/archives/iss/2004-q1/0157.html"},{"name":"10739","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/10739"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-2125","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Buffer overflow in blackd.exe for BlackICE PC Protection 3.6 and other versions before 3.6.ccb, with application protection off, allows local users to gain system privileges by modifying the .INI file to contain a long packetLog.fileprefix value."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"blackice-blackdexe-bo(14965)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/14965"},{"name":"9514","refsource":"BID","url":"http://www.securityfocus.com/bid/9514"},{"name":"3740","refsource":"OSVDB","url":"http://www.osvdb.org/3740"},{"name":"20040128 SRT2004-01-17-0227 - BlackICE allows local users to become SYSTEM","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=107530966524193&w=2"},{"name":"[ISSForum] 20040128 Third party BlackICE advisory","refsource":"MLIST","url":"http://archives.neohapsis.com/archives/iss/2004-q1/0157.html"},{"name":"10739","refsource":"SECUNIA","url":"http://secunia.com/advisories/10739"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-2125","datePublished":"2005-05-27T04:00:00.000Z","dateReserved":"2005-05-27T00:00:00.000Z","dateUpdated":"2024-08-08T01:15:01.601Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":true,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:iss:blackice_agent_server:3.6eca:*:*:*:*:*:*:*","matchCriteriaId":"68D71B50-D280-4735-BFFE-2548C3117D70"},{"vulnerable":true,"criteria":"cpe:2.3:a:iss:blackice_pc_protection:3.6cbd:*:*:*:*:*:*:*","matchCriteriaId":"D62AC2AC-E7ED-498B-805F-2300B9793C2E"},{"vulnerable":true,"criteria":"cpe:2.3:a:iss:blackice_server_protection:3.6cbz:*:*:*:*:*:*:*","matchCriteriaId":"E33242A8-7BE6-4A69-A7CC-81BAFC2ADD50"},{"vulnerable":true,"criteria":"cpe:2.3:a:iss:realsecure_desktop:3.6eca:*:*:*:*:*:*:*","matchCriteriaId":"CF2247F3-0287-40DC-8CE8-3D0E15910056"},{"vulnerable":true,"criteria":"cpe:2.3:a:iss:realsecure_desktop:7.0ebg:*:*:*:*:*:*:*","matchCriteriaId":"1F9233FA-D30A-4D0B-9605-CAA119C97CC9"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"2125","Ordinal":"1","Title":"CVE-2004-2125","CVE":"CVE-2004-2125","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"2125","Ordinal":"1","NoteData":"Buffer overflow in blackd.exe for BlackICE PC Protection 3.6 and other versions before 3.6.ccb, with application protection off, allows local users to gain system privileges by modifying the .INI file to contain a long packetLog.fileprefix value.","Type":"Description","Title":"CVE-2004-2125"},{"CveYear":"2004","CveId":"2125","Ordinal":"2","NoteData":"2005-05-27","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"2125","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}