Bug: ISS BlackICE PC Protection DLL faking of run-time linked libraries Vulnerability (WLB-2006080047 Ascii Version)

English Version
WLB2

CVE WLB2

 Topic: ISS BlackICE PC Protection DLL faking of run-time linked libraries Vulnerability
 Credit: David Matousek (david matousec com)
 Date: 2006.08.08
 CWE: N/A
 CVE: CVE-2006-3999 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
Medium
Yes
No

BlackICE does not protect pamversion.dll in its installation directory. And also because its component
protection fails to protect BlackICE processes this can be misused to inject fake DLL into BlackICE service.

The whole advisory with more details and source code is available here
http://www.matousec.com/info/advisories/BlackICE-DLL-faking-of-run-time-
linked-libraries.php

Regards,

--
David Matousek

Founder and Chief Representative of Matousec - Transparent security
http://www.matousec.com/

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com