PT-2005-4097 · Kerio · Kerio Personal Firewall+2
Piotr Bania
·
Published
2005-10-23
·
Updated
2012-12-13
·
CVE-2005-3286
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Kerio Personal Firewall version 4.2
Kerio Server Firewall version 1.1.1
Description
The issue allows local users to cause a denial of service by setting specific protection on the Page Environment Block (PEB), which triggers an exception. This is related to the FWDRV driver.
Recommendations
For Kerio Personal Firewall version 4.2, consider disabling the FWDRV driver as a temporary workaround until a patch is available.
For Kerio Server Firewall version 1.1.1, restrict access to the FWDRV driver to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fwdrv Driver
Kerio Personal Firewall
Kerio Serverfirewall