Press CTRL-D to bookmark us
Welcome Guest Login / Register / Members
Search in  
Top Submit newsSubscribe
Communication | Computer Crime | Digital Audio, Video, Photo | General News | Hardware | Internet | Mobile | PDA | Security | Software | Vulnerability |


Previous articleBack to news listNext article
 

 Sponsored links

Want to become one of our authors and see your work published on ALLSeek.iNFO ?
 
 Kerio Personal Firewall Administration Menu Lets Local Users Run Applications With SYSTEM Privileges
Categorie: Vulnerability
Posted: 2004-01-29 by ReCall
Views: 334
Source: Click here
 
Current Rating: Not rated
Poor Best
 Details
Description: Johan Tuneld reported a vulnerability in the Kerio Personal Firewall version 2.x. A local user can run commands with SYSTEM privileges.

It is reported that a local user can use the administrative menus to run a copy of 'cmd.exe' with SYSTEM level privileges. A user can go to the Administration > Miscellaneous menu, select the 'Load' button, browse to 'c:windowssystem32cmd.exe', right-click on 'cmd.exe', and then select 'Open' to open a command window with SYSTEM privileges.

A demonstration exploit screen shot is provided at:

http://www.tuneld.com/_images/other/kpf_system_privileges.png

If a firewall password is used, the local user must be authenticated to the firewall
before exploiting this flaw.

[Editor's note: The vulnerability reportedly applies to version 2. It is not clear if more recent versions of the firewall are also affected or not.]

Impact: A local user can open a Windows command window (cmd.exe) with SYSTEM privileges.

Solution: No solution was available at the time of this entry.
 
Syndication
Permalink Email this

The URI to TrackBack this entry is:
http://allseek.info/news/trackback.php?id=682

User comments (post your comments here)

Only registerd members can post comments and articles
 

Previous articleBack to news listNext article
 



InterJOB.su

SpyLOG Page Rank Checker
LAST QUERIES