Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Kerio Personal Firewall (KPF) 2.1.5 allows local users to execute arbitrary code with SYSTEM privileges via the Load button in the Firewall Configuration Files option, which does not drop privileges before opening the file loading dialog box.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Kerio Personal Firewall本地权限提升漏洞
Vulnerability Description
Kerio Personal Firewall是一款个人防火墙。 Kerio Personal Firewall存在权限提升漏洞,允许本地攻击者以高权限执行任意命令(一般是SYSTEM权限)。 攻击者只要打开KPF管理窗口,然后使用"Load"按钮(用于装载.conf文件导入规则)可浏览"c:\windows\system32\"文件夹中的CMD.EXE命令,并执行,就可以以高权限访问控制系统。
CVSS Information
N/A
Vulnerability Type
N/A