CVE-2006-6622
CVE-2006-6622
Soft4Ever Look 'n' Stop (LnS) 2.05p2 before 20061215 relies on the Process Environment Block (PEB) to identify a process, which allows local users to bypass the product's controls on a process by spoofing the (1) ImagePathName, (2) CommandLine, and (3) WindowTitle fields in the PEB.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://www.matousec.com/downloads/windows-personal-firewall-analysis/ex-coat.ziphttp://www.matousec.com/info/advisories/Bypassing-process-identification-serveral-personal-firewalls-HIPS.phphttp://www.securityfocus.com/archive/1/454522/100/0/threadedhttp://www.securityfocus.com/bid/21615http://www.wilderssecurity.com/showthread.php?t=158155