{"api_version":"1","generated_at":"2026-04-23T22:07:55+00:00","cve":"CVE-2004-2329","urls":{"html":"https://cve.report/CVE-2004-2329","api":"https://cve.report/api/cve/CVE-2004-2329.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-2329","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-2329"},"summary":{"title":"CVE-2004-2329","description":"Kerio Personal Firewall (KPF) 2.1.5 allows local users to execute arbitrary code with SYSTEM privileges via the Load button in the Firewall Configuration Files option, which does not drop privileges before opening the file loading dialog box.","state":"PUBLISHED","assigner":"mitre","published_at":"2004-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.2","severity":"","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.osvdb.org/3748","name":"http://www.osvdb.org/3748","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/14981","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/14981","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/alerts/2004/Jan/1008870.html","name":"http://www.securitytracker.com/alerts/2004/Jan/1008870.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"SecurityTracker.com Archives - Kerio Personal Firewall Administration Menu Lets Local Users Run Applications With SYSTEM Privileges","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.tuneld.com/_images/other/kpf_system_privileges.png","name":"http://www.tuneld.com/_images/other/kpf_system_privileges.png","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"404 Not Found","mime":"image/png","httpstatus":"404","archivestatus":"200"},{"url":"http://secunia.com/advisories/10746/","name":"http://secunia.com/advisories/10746/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - Kerio Personal Firewall Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.tuneld.com/news/?id=30","name":"http://www.tuneld.com/news/?id=30","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"404 Not Found","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/9525","name":"http://www.securityfocus.com/bid/9525","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Kerio Personal Firewall Local Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-2329","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-2329","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"2329","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"kerio","cpe5":"personal_firewall","cpe6":"2.1.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T01:22:13.679Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"9525","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/9525"},{"name":"kerio-pf-gain-privileges(14981)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/14981"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.tuneld.com/news/?id=30"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.tuneld.com/_images/other/kpf_system_privileges.png"},{"name":"1008870","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/alerts/2004/Jan/1008870.html"},{"name":"3748","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/3748"},{"name":"10746","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/10746/"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-01-27T00:00:00.000Z","descriptions":[{"lang":"en","value":"Kerio Personal Firewall (KPF) 2.1.5 allows local users to execute arbitrary code with SYSTEM privileges via the Load button in the Firewall Configuration Files option, which does not drop privileges before opening the file loading dialog box."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"9525","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/9525"},{"name":"kerio-pf-gain-privileges(14981)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/14981"},{"tags":["x_refsource_MISC"],"url":"http://www.tuneld.com/news/?id=30"},{"tags":["x_refsource_MISC"],"url":"http://www.tuneld.com/_images/other/kpf_system_privileges.png"},{"name":"1008870","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/alerts/2004/Jan/1008870.html"},{"name":"3748","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/3748"},{"name":"10746","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/10746/"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-2329","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Kerio Personal Firewall (KPF) 2.1.5 allows local users to execute arbitrary code with SYSTEM privileges via the Load button in the Firewall Configuration Files option, which does not drop privileges before opening the file loading dialog box."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"9525","refsource":"BID","url":"http://www.securityfocus.com/bid/9525"},{"name":"kerio-pf-gain-privileges(14981)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/14981"},{"name":"http://www.tuneld.com/news/?id=30","refsource":"MISC","url":"http://www.tuneld.com/news/?id=30"},{"name":"http://www.tuneld.com/_images/other/kpf_system_privileges.png","refsource":"MISC","url":"http://www.tuneld.com/_images/other/kpf_system_privileges.png"},{"name":"1008870","refsource":"SECTRACK","url":"http://www.securitytracker.com/alerts/2004/Jan/1008870.html"},{"name":"3748","refsource":"OSVDB","url":"http://www.osvdb.org/3748"},{"name":"10746","refsource":"SECUNIA","url":"http://secunia.com/advisories/10746/"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-2329","datePublished":"2005-08-16T04:00:00.000Z","dateReserved":"2005-08-16T00:00:00.000Z","dateUpdated":"2024-08-08T01:22:13.679Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:kerio:personal_firewall:2.1.5:*:*:*:*:*:*:*","matchCriteriaId":"FCE7ABB0-44E8-40DA-A94C-2F9530497D78"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"2329","Ordinal":"1","Title":"CVE-2004-2329","CVE":"CVE-2004-2329","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"2329","Ordinal":"1","NoteData":"Kerio Personal Firewall (KPF) 2.1.5 allows local users to execute arbitrary code with SYSTEM privileges via the Load button in the Firewall Configuration Files option, which does not drop privileges before opening the file loading dialog box.","Type":"Description","Title":"CVE-2004-2329"},{"CveYear":"2004","CveId":"2329","Ordinal":"2","NoteData":"2005-08-16","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"2329","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}