← Vulnerability feed

Vulnerability record · CVE-2004-1714 · published 11 August 2004

CVE-2004-1714: Iss blackice pc protection incorrect permission assignment vulnerability

Iss · Blackice Pc Protection

BlackICE PC Protection and Server Protection installs (1) firewall.ini, (2) blackice.ini, (3) sigs.ini and (4) protect.ini with Everyone Full Control permissions, which allows local users to cause a denial of service (crash) or modify configuration, as demonstrated by modifying firewall.ini to contain a large firewall rule.

7.1 CVSS 3.1 High EPSS 0.85% · top 43.5% CWE-732 · Incorrect permission assignment
7.1CVSS 3.1 base score, v2 2.1
0.85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
8References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

BlackICE PC Protection and Server Protection installs (1) firewall.ini, (2) blackice.ini, (3) sigs.ini and (4) protect.ini with Everyone Full Control permissions, which allows local users to cause a denial of service (crash) or modify configuration, as demonstrated by modifying firewall.ini to contain a large firewall rule.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2004-1714 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2004-0362ISS PAM ICQ Parsing Stack Buffer Overflows Allow Remote Code ExecutionThe ISS Protocol Analysis Module (PAM) used in RealSecure, Proventia and BlackICE products contains multiple stack-based buffer overflows in its ICQ …EPSS 73%analysed7.5CVE-2004-0193Iss blackice agent server vulnerabilityHeap-based buffer overflow in the ISS Protocol Analysis Module (PAM), as used in certain versions of RealSecure Network 7.0 and Server Sensor 7.0, Pr…EPSS 8.0%7.2CVE-2005-2711Iss blackice agent server vulnerabilityISS BlackIce 3.6, as used in multiple products including BlackICE PC Protection, Server Protection, Agent for Server, and RealSecure Desktop 3.6 and …EPSS 0.37%5.0CVE-2006-3840Iss blackice pc protection vulnerabilityThe SMB Mailslot parsing functionality in PAM in multiple ISS products with XPU (24.39/1.78/epj/x.x.x.1780), including Proventia A, G, M, Server, and…EPSS 2.4%4.6CVE-2006-4541Iss blackice pc protection improper input validation vulnerabilityRapDrv.sys in BlackICE PC Protection 3.6.cpn, cpj, cpiE, and possibly 3.6 and earlier, allows local users to cause a denial of service (crash) via a …EPSS 0.73%4.6CVE-2006-3999Iss blackice pc protection vulnerabilityISS BlackICE PC Protection 3.6.cpj, 3.6.cpiE, and possibly earlier versions do not properly monitor the integrity of the pamversion.dll BlackICE libr…EPSS 0.33%4.6CVE-2004-2125Iss blackice agent server vulnerabilityBuffer overflow in blackd.exe for BlackICE PC Protection 3.6 and other versions before 3.6.ccb, with application protection off, allows local users t…EPSS 0.42%4.6CVE-2004-2126Iss blackice pc protection vulnerabilityThe upgrade for BlackICE PC Protection 3.6 and earlier sets insecure permissions for .INI files such as (1) blackice.ini, (2) firewall.ini, (3) prote…EPSS 0.43%

Source: NIST National Vulnerability Database (record CVE-2004-1714), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.