PT-2004-2022 · Kerio · Kerio Serverfirewall+2

Publicado

2004-12-15

·

Atualizado

2017-07-11

·

CVE-2004-1023

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Kerio Winroute Firewall versions prior to 6.0.9 Kerio ServerFirewall versions prior to 1.0.1 Kerio MailServer versions prior to 6.0.5
Description: The issue allows local users with Power Users privileges to modify critical files due to unmodified ACLs. This enables them to alter programs, install malicious DLLs in the plug-ins folder, and modify XML configuration files.
Recommendations: For Kerio Winroute Firewall versions prior to 6.0.9, update to version 6.0.9 or later to resolve the issue. For Kerio ServerFirewall versions prior to 1.0.1, update to version 1.0.1 or later to resolve the issue. For Kerio MailServer versions prior to 6.0.5, update to version 6.0.5 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-1023

Produtos afetados

Kerio Mailserver
Kerio Serverfirewall
Kerio Winroute Firewall