CVE-2006-7160: Input Validation
The Sandbox.sys driver in Outpost Firewall PRO 4.0, and possibly earlier versions, does not validate arguments to hooked SSDT functions, which allows local users to cause a denial of service (crash) via invalid arguments to the (1) NtAssignProcessToJobObject,, (2) NtCreateKey, (3) NtCreateThread, (4) NtDeleteFile, (5) NtLoadDriver, (6) NtOpenProcess, (7) NtProtectVirtualMemory, (8) NtReplaceKey, (9) NtTerminateProcess, (10) NtTerminateThread, (11) NtUnloadDriver, and (12) NtWriteVirtualMemory functions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-7160?
CVE-2006-7160 is classified as a high severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2006-7160?
To fix CVE-2006-7160, update to a version of Agnitum Outpost Firewall PRO later than 4.0 that addresses this vulnerability.
Who is affected by CVE-2006-7160?
CVE-2006-7160 affects local users of Outpost Firewall PRO 4.0 and possibly earlier versions.
What is the impact of CVE-2006-7160?
The impact of CVE-2006-7160 is the potential for local users to crash the system by sending invalid arguments to specific functions.
Is CVE-2006-7160 exploitable remotely?
CVE-2006-7160 is not exploitable remotely as it requires local user access to trigger the vulnerability.