First published: Tue May 02 2017(Updated: )
Kerio Connect 8.0.0 through 9.2.2, and Kerio Connect Client desktop application for Windows and Mac 9.2.0 through 9.2.2, when e-mail preview is enabled, allows remote attackers to conduct clickjacking attacks via a crafted e-mail message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GFI KerioConnect | =8.0.0 | |
GFI KerioConnect | =8.0.1 | |
GFI KerioConnect | =8.0.2 | |
GFI KerioConnect | =8.1.0 | |
GFI KerioConnect | =8.1.1 | |
GFI KerioConnect | =8.1.2 | |
GFI KerioConnect | =8.1.3 | |
GFI KerioConnect | =8.2.0 | |
GFI KerioConnect | =8.2.1 | |
GFI KerioConnect | =8.2.2 | |
GFI KerioConnect | =8.2.3 | |
GFI KerioConnect | =8.2.4 | |
GFI KerioConnect | =8.3.0 | |
GFI KerioConnect | =8.3.1 | |
GFI KerioConnect | =8.3.2 | |
GFI KerioConnect | =8.3.3 | |
GFI KerioConnect | =8.3.4 | |
GFI KerioConnect | =8.4.0 | |
GFI KerioConnect | =8.4.1 | |
GFI KerioConnect | =8.4.2 | |
GFI KerioConnect | =8.4.3 | |
GFI KerioConnect | =8.5.0 | |
GFI KerioConnect | =8.5.1 | |
GFI KerioConnect | =8.5.2 | |
GFI KerioConnect | =8.5.3 | |
GFI KerioConnect | =9.0.0 | |
GFI KerioConnect | =9.0.1 | |
GFI KerioConnect | =9.0.2 | |
GFI KerioConnect | =9.0.3 | |
GFI KerioConnect | =9.0.4 | |
GFI KerioConnect | =9.1.0 | |
GFI KerioConnect | =9.1.1 | |
GFI KerioConnect | =9.2.0 | |
GFI KerioConnect | =9.2.1 | |
GFI KerioConnect | =9.2.2 | |
Kerio Connect Client | =9.2.0 | |
Kerio Connect Client | =9.2.1 | |
Kerio Connect Client | =9.2.2 | |
GFI Kerio Connect Client | >=8.0.0<=9.2.2 | |
All of | ||
Kerio Connect Client | >=9.2.0<=9.2.2 | |
Any of | ||
macOS | ||
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7440 is classified as a medium severity vulnerability due to its potential for clickjacking attacks.
To mitigate CVE-2017-7440, upgrade Kerio Connect to version 9.2.3 or later.
CVE-2017-7440 affects Kerio Connect versions 8.0.0 through 9.2.2.
Yes, remote attackers can exploit CVE-2017-7440 to conduct clickjacking attacks via crafted email messages.
Yes, the Kerio Connect Client desktop application for Windows and Mac versions 9.2.0 through 9.2.2 is also affected.