Kerio Personal Firewall Administration Menu Lets Local Users Run Applications With SYSTEM Privileges
Categorie: Vulnerability Posted: 2004-01-29 by ReCall Views: 334 Source: Click here
Current Rating: Not rated
Details
Description: Johan Tuneld reported a vulnerability in the Kerio Personal Firewall version 2.x. A local user can run commands with SYSTEM privileges.
It is reported that a local user can use the administrative menus to run a copy of 'cmd.exe' with SYSTEM level privileges. A user can go to the Administration > Miscellaneous menu, select the 'Load' button, browse to 'c:windowssystem32cmd.exe', right-click on 'cmd.exe', and then select 'Open' to open a command window with SYSTEM privileges.
A demonstration exploit screen shot is provided at: