CVE-2006-7160

4.9
CVSS v2.0 Base Score
0.37%
LOW RiskEPSS (28th percentile)

The Sandbox.sys driver in Outpost Firewall PRO 4.0, and possibly earlier versions, does not validate arguments to hooked SSDT functions, which allows local users to cause a denial of service (crash) via invalid arguments to the (1) NtAssignProcessToJobObject,, (2) NtCreateKey, (3) NtCreateThread, (4) NtDeleteFile, (5) NtLoadDriver, (6) NtOpenProcess, (7) NtProtectVirtualMemory, (8) NtReplaceKey, (9) NtTerminateProcess, (10) NtTerminateThread, (11) NtUnloadDriver, and (12) NtWriteVirtualMemory functions.

Published: 3/7/2007
Modified: 6/16/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v2 Score

4.9

AV:L/AC:L/Au:N/C:N/I:N/A:C

EPSS Score (Exploitation Probability)

0.37%LOW Exploitation Risk
28th percentile

This vulnerability has a 0.37% probability of being exploited in the next 30 days, ranking higher than 28% of all scored CVEs.

CWE Classification

Advertisement