Internet Security Systems BlackICE Local Denial of Service Vulnerability
BID:19800
CVE-2006-4541 |Info
Internet Security Systems BlackICE Local Denial of Service Vulnerability
| Bugtraq ID: | 19800 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-4541 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 01 2006 12:00AM |
| Updated: | Sep 18 2007 09:20PM |
| Credit: | David Matousek is credited with the discovery of this vulnerability. |
| Vulnerable: |
Internet Security Systems BlackICE PC Protection 3.6 cch Internet Security Systems BlackICE PC Protection 3.6 ccg Internet Security Systems BlackICE PC Protection 3.6 ccf Internet Security Systems BlackICE PC Protection 3.6 cce Internet Security Systems BlackICE PC Protection 3.6 ccd Internet Security Systems BlackICE PC Protection 3.6 ccc Internet Security Systems BlackICE PC Protection 3.6 ccb Internet Security Systems BlackICE PC Protection 3.6 cca Internet Security Systems BlackICE PC Protection 3.6 cbz Internet Security Systems BlackICE PC Protection 3.6 cbr Internet Security Systems BlackICE PC Protection 3.6 cbd Internet Security Systems BlackICE PC Protection 3.6 .cno Internet Security Systems BlackICE PC Protection 3.6 .cbz |
| Not Vulnerable: | |
Discussion
Internet Security Systems BlackICE Local Denial of Service Vulnerability
Internet Security Systems (ISS) BlackICE PC Protection is prone to a local denial-of-service vulnerability because the application fails to properly sanitize user-supplied input.
This vulnerability allows local attackers to crash affected systems, facilitating a denial-of-service condition on the local computer. Remote code execution may also be possible if the vulnerability is exploited in privileged kernel mode.
Versions 3.6.cpn, 3.6.cpj, and 3.6.cpiE are vulnerable to this issue; other versions may also be affected.
Internet Security Systems (ISS) BlackICE PC Protection is prone to a local denial-of-service vulnerability because the application fails to properly sanitize user-supplied input.
This vulnerability allows local attackers to crash affected systems, facilitating a denial-of-service condition on the local computer. Remote code execution may also be possible if the vulnerability is exploited in privileged kernel mode.
Versions 3.6.cpn, 3.6.cpj, and 3.6.cpiE are vulnerable to this issue; other versions may also be affected.
Exploit / POC
Internet Security Systems BlackICE Local Denial of Service Vulnerability
The following proof-of-concept code demonstrates this issue:
The following proof-of-concept code demonstrates this issue:
Solution / Fix
Internet Security Systems BlackICE Local Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
Internet Security Systems BlackICE Local Denial of Service Vulnerability
References:
References:
- BlackICE Homepage (Internet Security Systems)
- BlackICE Insufficient validation of arguments of NtOpenSection Vulnerability (David Matousek)
- Windows Personal Firewall Analysis (Matousec)
- ISS BlackICE PC Protection Insufficient validation of arguments of NtOpenSection (David Matousek)
- Plague in (security) software drivers & BSDOhook utility (Matousec)