First published: Tue Sep 05 2006(Updated: )
RapDrv.sys in BlackICE PC Protection 3.6.cpn, cpj, cpiE, and possibly 3.6 and earlier, allows local users to cause a denial of service (crash) via a NULL third argument to the NtOpenSection API function. NOTE: it was later reported that 3.6.cqn is also affected.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM ISS BlackICE PC Protection | =3.6cpie | |
IBM ISS BlackICE PC Protection | =3.6cpj | |
IBM ISS BlackICE PC Protection | =3.6cpn | |
IBM ISS BlackICE PC Protection | <=3.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4541 is classified as a high severity vulnerability due to its capability to cause a denial of service.
To fix CVE-2006-4541, upgrade to a version of BlackICE PC Protection that is not affected by this vulnerability.
CVE-2006-4541 affects various versions of ISS BlackICE PC Protection up to 3.6, including specific versions like 3.6.cpn, 3.6.cpj, and 3.6.cpie.
CVE-2006-4541 is a local denial of service vulnerability caused by insufficient validation of arguments in the NtOpenSection API.
CVE-2006-4541 cannot be exploited remotely as it requires local access to the affected system.