7.2

CVE-2006-6621

Filseclab Personal Firewall 3.0.0.8686 relies on the Process Environment Block (PEB) to identify a process, which allows local users to bypass the product's controls on a process by spoofing the (1) ImagePathName, (2) CommandLine, and (3) WindowTitle fields in the PEB.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Avg ≫ Antivirus Plus Firewall Version 7.5.431
Comodo ≫ Comodo Personal Firewall Version 2.3.6.81
Filseclab ≫ Personal Firewall Version 3.0.8686
Infoprocess ≫ Antihook Version 3.0.23
Soft4ever ≫ Look N Stop Version 2.05p2
Symantec ≫ Sygate Personal Firewall Version 5.6.2808
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.24
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.matousec.com/downloads/windows-personal-firewall-analysis/ex-coat.zip
http://www.matousec.com/info/advisories/Bypassing-process-identification-serveral-personal-firewalls-HIPS.php
Vendor Advisory
http://www.securityfocus.com/archive/1/454522/100/0/threaded
http://www.securityfocus.com/bid/21615