The Sandbox.sys driver in Outpost Firewall PRO 4.0, and possibly earlier versions, does not validate arguments to hooked SSDT functions, which allows local users to cause a denial of service (crash) via invalid arguments to the (1) NtAssignProcessToJobObject,, (2) NtCreateKey, (3) NtCreateThread, (4) NtDeleteFile, (5) NtLoadDriver, (6) NtOpenProcess, (7) NtProtectVirtualMemory, (8) NtReplaceKey, (9) NtTerminateProcess, (10) NtTerminateThread, (11) NtUnloadDriver, and (12) NtWriteVirtualMemory functions.
                
            References
                    Configurations
                    Information
                Published : 2007-03-07 12:19
Updated : 2018-10-16 09:29
NVD link : CVE-2006-7160
Mitre link : CVE-2006-7160
JSON object : View
CWE
                
                    
                        
                        CWE-20
                        
            Improper Input Validation
Products Affected
                agnitum
- outpost_firewall


