Poll
Should software vendors reward independent researchers for finding vulnerabilities in their software?
Advisory 2006-08-01.01
BlackICE DLL faking of run-time linked libraries Vulnerability
Basic information:
Release date: August 01, 2006
Last update: September 19, 2006
Severity:Critical
Character:Complete system control
Status:Unknown
Testing program: BTP00022P003BI.zip
Description:
BlackICE implements application component protection for privileged programs but it fails to protect some of its own processes. Moreover, it does not protect file 'pamversion.dll' in its own installation directory against actions of other processes. It is possible to replace this DLL with a fake library. The main BlackICE service 'blackd.exe' dynamically loads this library into its own process during the initialization of BlackICE after the system start. Hence it is possible to inject the fake library into the BlackICE service and gain a complete control of the protection system.
Vulnerable software:
- BlackICE PC Protection 3.6.cpj
- BlackICE PC Protection 3.6.cpiE
- Proventia Desktop 8.0
- Proventia Server - any version
- RealSecure Desktop 7.0
- probably all versions of BlackICE PC Protection 3.6
- possibly older versions of BlackICE PC Protection
Events:
- 2006-08-04: Candidate for inclusion in the CVE list
- 2006-08-04: Vulnerability confirmed by popular information sources
- 2006-08-01: Advisory released
- 2006-08-01: Vendor notification