← Vulnerability feed

Vulnerability record · CVE-2005-2711 · published 31 December 2005

CVE-2005-2711: Iss blackice agent server vulnerability

Iss · Blackice Agent Server

ISS BlackIce 3.6, as used in multiple products including BlackICE PC Protection, Server Protection, Agent for Server, and RealSecure Desktop 3.6 and 7.0, does not drop privileges before launching help from the "More Info" button in the "Application Protection" dialog, which allows local users to execute arbitrary programs as SYSTEM.

7.2 CVSS 2.0 High EPSS 0.37% · top 72.0%
7.2CVSS 2.0 base score
0.37%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
16References
16 Jun 2026Last modified by NVD

Description

ISS BlackIce 3.6, as used in multiple products including BlackICE PC Protection, Server Protection, Agent for Server, and RealSecure Desktop 3.6 and 7.0, does not drop privileges before launching help from the "More Info" button in the "Application Protection" dialog, which allows local users to execute arbitrary programs as SYSTEM.

AV:L/AC:L/Au:N/C:C/I:C/A:C

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-2711 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2004-0362ISS PAM ICQ Parsing Stack Buffer Overflows Allow Remote Code ExecutionThe ISS Protocol Analysis Module (PAM) used in RealSecure, Proventia and BlackICE products contains multiple stack-based buffer overflows in its ICQ …EPSS 73%analysed7.5CVE-2004-0193Iss blackice agent server vulnerabilityHeap-based buffer overflow in the ISS Protocol Analysis Module (PAM), as used in certain versions of RealSecure Network 7.0 and Server Sensor 7.0, Pr…EPSS 8.0%7.1CVE-2004-1714Iss blackice pc protection incorrect permission assignment vulnerabilityBlackICE PC Protection and Server Protection installs (1) firewall.ini, (2) blackice.ini, (3) sigs.ini and (4) protect.ini with Everyone Full Control…EPSS 0.85%5.0CVE-2006-3840Iss blackice pc protection vulnerabilityThe SMB Mailslot parsing functionality in PAM in multiple ISS products with XPU (24.39/1.78/epj/x.x.x.1780), including Proventia A, G, M, Server, and…EPSS 2.4%4.6CVE-2006-4541Iss blackice pc protection improper input validation vulnerabilityRapDrv.sys in BlackICE PC Protection 3.6.cpn, cpj, cpiE, and possibly 3.6 and earlier, allows local users to cause a denial of service (crash) via a …EPSS 0.73%4.6CVE-2006-3999Iss blackice pc protection vulnerabilityISS BlackICE PC Protection 3.6.cpj, 3.6.cpiE, and possibly earlier versions do not properly monitor the integrity of the pamversion.dll BlackICE libr…EPSS 0.33%4.6CVE-2004-2125Iss blackice agent server vulnerabilityBuffer overflow in blackd.exe for BlackICE PC Protection 3.6 and other versions before 3.6.ccb, with application protection off, allows local users t…EPSS 0.42%4.6CVE-2004-2126Iss blackice pc protection vulnerabilityThe upgrade for BlackICE PC Protection 3.6 and earlier sets insecure permissions for .INI files such as (1) blackice.ini, (2) firewall.ini, (3) prote…EPSS 0.43%

Source: NIST National Vulnerability Database (record CVE-2005-2711), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.