Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Internet Security Systems BlackICE PC Protection blackd.exe Local Buffer Overrun Vulnerability

It is reported that BlackICE PC Protection is prone to a locally exploitable buffer overrun when handling excessive input in certain configuration directives for various .ini files included with the software. While these files are allegedly not writeable by non-administrative users in the default install, it has been reported that they may be globally writeable by all system users after a software upgrade (as described in BID 9513).

Given the ability of a local attacker to modify the contents of these files, it will be possible to execute arbitrary with SYSTEM privileges since these files are parsed by the blackd.exe process, which runs in SYSTEM context.

This issue could also be exploited remotely if an attacker can exploit other vulnerabilities to cause a malicious version of a .ini file to be placed on the local system. This might occur through exploitation of latent vulnerabilities in Internet Explorer, such as those described in BID 8577.







 

Privacy Statement
Copyright 2009, SecurityFocus