CVE-2005-3286: Low severity Kerio Personal Firewall vulnerability
The FWDRV driver in Kerio Personal Firewall 4.2 and Server Firewall 1.1.1 allows local users to cause a denial of service (crash) by setting the PAGENOACCESS or PAGEGUARD protection on the Page Environment Block (PEB), which triggers an exception, aka the "PEB lockout vulnerability."
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-3286?
CVE-2005-3286 is classified as a denial of service vulnerability that can cause the affected software to crash.
How do I fix CVE-2005-3286?
To mitigate CVE-2005-3286, users should upgrade to a patched version of Kerio Personal Firewall or Kerio Server Firewall.
What products are affected by CVE-2005-3286?
CVE-2005-3286 affects Kerio Personal Firewall version 4.2 and Kerio Server Firewall version 1.1.1.
Can CVE-2005-3286 be exploited remotely?
CVE-2005-3286 is a local vulnerability that requires access from a local user to be exploited.
What is the impact of a successful exploit of CVE-2005-3286?
A successful exploit of CVE-2005-3286 results in a denial of service condition, causing the application to crash.