CVE-2005-2711

UnknownEPSS 0.37%

Last modified

CVE-2005-2711 is a vulnerability of currently unknown severity. ISS BlackIce 3.6, as used in multiple products including BlackICE PC Protection, Server Protection, Agent for Server, and RealSecure Desktop 3.6 and 7.0, does not drop privileges before launching help from the "More Info" button in the "Application Protection" dialog, which allows local users to execute arbitrary programs as SYSTEM.. EPSS estimates a 0.37% chance of exploitation in the next 30 days.

Description

ISS BlackIce 3.6, as used in multiple products including BlackICE PC Protection, Server Protection, Agent for Server, and RealSecure Desktop 3.6 and 7.0, does not drop privileges before launching help from the "More Info" button in the "Application Protection" dialog, which allows local users to execute arbitrary programs as SYSTEM.

Metrics

EPSS Probability
0.37%

28.7th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
IssBlackice Agent ServerAll versions
IssBlackice Pc Protection3.6
IssBlackice Pc Protection3.6cpu
IssBlackice Server ProtectionAll versions
IssRealsecure Desktop3.6
IssRealsecure Desktop7.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2005-2711?
ISS BlackIce 3.6, as used in multiple products including BlackICE PC Protection, Server Protection, Agent for Server, and RealSecure Desktop 3.6 and 7.0, does not drop privileges before launching help from the "More Info" button in the "Application Protection" dialog, which allows local users to execute arbitrary programs as SYSTEM.
How severe is CVE-2005-2711?
Severity scoring for CVE-2005-2711 is pending analysis. The EPSS model estimates a 0.37% probability of exploitation in the next 30 days.
How do I fix CVE-2005-2711?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2005-2711?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST