CVE-2006-4541: Input Validation
RapDrv.sys in BlackICE PC Protection 3.6.cpn, cpj, cpiE, and possibly 3.6 and earlier, allows local users to cause a denial of service (crash) via a NULL third argument to the NtOpenSection API function. NOTE: it was later reported that 3.6.cqn is also affected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4541?
CVE-2006-4541 is classified as a high severity vulnerability due to its capability to cause a denial of service.
How do I fix CVE-2006-4541?
To fix CVE-2006-4541, upgrade to a version of BlackICE PC Protection that is not affected by this vulnerability.
What systems are affected by CVE-2006-4541?
CVE-2006-4541 affects various versions of ISS BlackICE PC Protection up to 3.6, including specific versions like 3.6.cpn, 3.6.cpj, and 3.6.cpie.
What type of vulnerability is CVE-2006-4541?
CVE-2006-4541 is a local denial of service vulnerability caused by insufficient validation of arguments in the NtOpenSection API.
Can CVE-2006-4541 be exploited remotely?
CVE-2006-4541 cannot be exploited remotely as it requires local access to the affected system.