CVE-2006-3787: Low severity Kerio Personal Firewall vulnerability
kpf4ss.exe in Sunbelt Kerio Personal Firewall 4.3.x before 4.3.268 does not properly hook the CreateRemoteThread API function, which allows local users to cause a denial of service (crash) and bypass protection mechanisms by calling CreateRemoteThread.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3787?
CVE-2006-3787 has a low severity rating as it primarily causes denial of service without any elevated privileges required.
How do I fix CVE-2006-3787?
To mitigate CVE-2006-3787, update to Sunbelt Kerio Personal Firewall version 4.3.268 or later which addresses the vulnerability.
Who is affected by CVE-2006-3787?
Users of Sunbelt Kerio Personal Firewall versions prior to 4.3.268 are affected by CVE-2006-3787.
What does CVE-2006-3787 exploit?
CVE-2006-3787 exploits a failure in proper hooking of the CreateRemoteThread API function.
What is the impact of CVE-2006-3787?
The impact of CVE-2006-3787 is a potential denial of service due to application crashes.