|
Brought to you by:
Suppliers of:
|
|
|
| |
Sunbelt Kerio Personal Firewall is a popular firewall software for Windows systems.
A vulnerability in the Kerio Firewall software allows to crash its service, thus bypassing the firewall. |
| |
Credit:
The information has been provided by matousec.com.
The original article can be found at:
http://www.matousec.com/info/advisories/Kerio-Terminating-kpf4ss-exe-using-internal-runtime-error.php
|
| |
Vulnerable Systems:
* Sunbelt Kerio Personal Firewall 4.3.246
Immune Systems:
* Sunbelt Kerio Personal Firewall 4.3.268
* Sunbelt Kerio Personal Firewall 4.2.3.912
Kerio uses strange ring3 hooks that communicates the Kerio driver using an interrupt. Windows API CreateRemoteThread is hooked by Kerio in user mode in every process. Calling this API can cause a crash of the Kerio service 'kpf4ss.exe'. The cause of this behavior is unknown. The crash of the Kerio service equals to disabling the protection. The tray icon of Kerio is not functional any more after exploiting the bug, any application can perform arbitrary protected action including Internet access and process creation.
Disclosure Timeline:
* 2006-07-15: Vendor notification
* 2006-07-15: Advisory released
* 2006-07-17: Vulnerability confirmed by popular information sources
* 2006-07-17: Received request from the product vendor to temporarily remove the exploit code
|
|
|
|
|