Kerio Personal Firewall Application Security Bypass Vulnerability
BID:11096
Info
Kerio Personal Firewall Application Security Bypass Vulnerability
| Bugtraq ID: | 11096 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 02 2004 12:00AM |
| Updated: | Sep 02 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Tan Chew Keong of SIG^2 Vulnerability Research. |
| Vulnerable: |
Kerio Personal Firewall 4.0.16 Kerio Personal Firewall 4.0.10 Kerio Personal Firewall 4.0.9 Kerio Personal Firewall 4.0.8 Kerio Personal Firewall 4.0.7 Kerio Personal Firewall 4.0.6 |
| Not Vulnerable: | |
Discussion
Kerio Personal Firewall Application Security Bypass Vulnerability
A vulnerability is reported to affect Kerio Personal Firewall (KPF) 'Application Security' functionality that could permit an executable that is run by an administrator to disable KPF 'Application Security' functionality.
It is reported that (KPF) 'Application Security' functionality employs a modified Service Description Table in order to function. It is possible to restore the Service Description Table to its original state. A malicious application that is run by an administrator can read an intact SDT table from kernel memory and restore the SDT table in the running kernel by writing to kernel memory space. This will disable Kerio Personal Firewall (KPF) 'Application Security' functionality.
A vulnerability is reported to affect Kerio Personal Firewall (KPF) 'Application Security' functionality that could permit an executable that is run by an administrator to disable KPF 'Application Security' functionality.
It is reported that (KPF) 'Application Security' functionality employs a modified Service Description Table in order to function. It is possible to restore the Service Description Table to its original state. A malicious application that is run by an administrator can read an intact SDT table from kernel memory and restore the SDT table in the running kernel by writing to kernel memory space. This will disable Kerio Personal Firewall (KPF) 'Application Security' functionality.
Exploit / POC
Kerio Personal Firewall Application Security Bypass Vulnerability
It is reported that the following tool, SDTrestore, may be used to exploit this vulnerability:
http://www.security.org.sg/code/sdtrestore.html
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
It is reported that the following tool, SDTrestore, may be used to exploit this vulnerability:
http://www.security.org.sg/code/sdtrestore.html
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Kerio Personal Firewall Application Security Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Kerio Personal Firewall Application Security Bypass Vulnerability
References:
References:
- Kerio Homepage (Kerio)
- Kerio Personal Firewall's Application Launch Protection Can Be Disabled by Direc (SIG^2 Vulnerability Research)