Firewall rule vulnerability for Internet Security Config - 1382 and 1383 installers.

The Internet Security.cfgx file found in the 1382 and 1383 installers contains a new rule that allows the ‘All Applications’ file group all outgoing access, once the firewall is installed.

The bug/issue

    Attempting to resolve forum questions on firewall behaviour
    After working through the problem it became apparent there was a problem with the Internet security configuration.
    For this rule not to have been created.
    Delete the rule from the firewall or choose an alternative configuration file.
    Reproducible always.
    If this is by design it should be changed. The rule is not present in the Proactive or Firewall configuration files. The rule is also not added when upgrading from a previous version of CIS, such as 1355.

1383 Doesnt respect “custom policy” firewall selection/setting
Firewall settings not working - pleas help!

    Any 1382 or 1383 installer
    The rule is added either by installing the suite with the AV component (it defaults to Internet security) or by selecting Internet Security post installation.
    Windows 7 Ultimate x86 and x64. I haven’t tried XP, however, because the rule is in the cfgx file I don’t doubt the result will be the same.
