PT-2005-4097 · Kerio · Kerio Personal Firewall+2

Piotr Bania

·

Published

2005-10-23

·

Updated

2012-12-13

·

CVE-2005-3286

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Kerio Personal Firewall version 4.2 Kerio Server Firewall version 1.1.1
Description The issue allows local users to cause a denial of service by setting specific protection on the Page Environment Block (PEB), which triggers an exception. This is related to the FWDRV driver.
Recommendations For Kerio Personal Firewall version 4.2, consider disabling the FWDRV driver as a temporary workaround until a patch is available. For Kerio Server Firewall version 1.1.1, restrict access to the FWDRV driver to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-3286

Affected Products

Fwdrv Driver
Kerio Personal Firewall
Kerio Serverfirewall