CVE-2005-2711

high

Description

ISS BlackIce 3.6, as used in multiple products including BlackICE PC Protection, Server Protection, Agent for Server, and RealSecure Desktop 3.6 and 7.0, does not drop privileges before launching help from the "More Info" button in the "Application Protection" dialog, which allows local users to execute arbitrary programs as SYSTEM.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/25423

http://www.vupen.com/english/advisories/2006/1090

http://www.securityfocus.com/bid/17218

http://www.osvdb.org/24096

http://www.idefense.com/intelligence/vulnerabilities/display.php?id=403

http://securitytracker.com/id?1015821

http://securitytracker.com/id?1015820

http://secunia.com/advisories/19327

Details

Source: Mitre, NVD

Published: 2005-12-31

Updated: 2026-06-16

Risk Information

CVSS v2

Base Score: 7.2

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00064