MEDIUM · 6.6

CVE-2006-6797

The Client Server Run-Time Subsystem (CSRSS) in Microsoft Windows allows local users to cause a denial of service (crash) or read arbitrary memory from csrss.exe via crafted arguments to the NtRaiseHa...

Vulnerability Description

The Client Server Run-Time Subsystem (CSRSS) in Microsoft Windows allows local users to cause a denial of service (crash) or read arbitrary memory from csrss.exe via crafted arguments to the NtRaiseHardError function with status 0x50000018, a different vulnerability than CVE-2006-6696.

CVSS Score

6.6

MEDIUM

AV:L/AC:L/Au:N/C:C/I:N/A:C
Confidentiality
COMPLETE
Integrity
NONE
Availability
COMPLETE

Affected Products

VendorProductVersions
MicrosoftWindows XpAll versions

References

FAQ

What is CVE-2006-6797?

CVE-2006-6797 is a vulnerability with a CVSS score of 6.6 (MEDIUM). The Client Server Run-Time Subsystem (CSRSS) in Microsoft Windows allows local users to cause a denial of service (crash) or read arbitrary memory from csrss.exe via crafted arguments to the NtRaiseHa...

How severe is CVE-2006-6797?

CVE-2006-6797 has been rated MEDIUM with a CVSS base score of 6.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-6797?

Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Windows Xp.