HIGH · 7.2

CVE-2004-2329

Kerio Personal Firewall (KPF) 2.1.5 allows local users to execute arbitrary code with SYSTEM privileges via the Load button in the Firewall Configuration Files option, which does not drop privileges b...

Vulnerability Description

Kerio Personal Firewall (KPF) 2.1.5 allows local users to execute arbitrary code with SYSTEM privileges via the Load button in the Firewall Configuration Files option, which does not drop privileges before opening the file loading dialog box.

CVSS Score

7.2

HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
KerioPersonal Firewall2.1.5

References

FAQ

What is CVE-2004-2329?

CVE-2004-2329 is a vulnerability with a CVSS score of 7.2 (HIGH). Kerio Personal Firewall (KPF) 2.1.5 allows local users to execute arbitrary code with SYSTEM privileges via the Load button in the Firewall Configuration Files option, which does not drop privileges b...

How severe is CVE-2004-2329?

CVE-2004-2329 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-2329?

Check the references section above for vendor advisories and patch information. Affected products include: Kerio Personal Firewall.