Vulnerabilities > CVE-2006-3787 - Denial of Service vulnerability in Sunbelt Kerio Personal Firewall CreateRemoteThread

047910
CVSS 2.1 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
local
low complexity
kerio
exploit available

Summary

kpf4ss.exe in Sunbelt Kerio Personal Firewall 4.3.x before 4.3.268 does not properly hook the CreateRemoteThread API function, which allows local users to cause a denial of service (crash) and bypass protection mechanisms by calling CreateRemoteThread.

Vulnerable Configurations

Part Description Count
Application
Kerio
1

Exploit-Db

descriptionSunbelt Kerio Personal Firewall 4.3.426 CreateRemoteThread Denial of Service Vulnerability. CVE-2006-3787. Dos exploit for hardware platform
idEDB-ID:28228
last seen2016-02-03
modified2006-07-15
published2006-07-15
reporterDavid Matousek
sourcehttps://www.exploit-db.com/download/28228/
titleSunbelt Kerio Personal Firewall 4.3.426 CreateRemoteThread Denial of Service Vulnerability