CVE-2023-25267: Buffer Overflow
An issue was discovered in GFI Kerio Connect 9.4.1 patch 1 (fixed in 10.0.0). There is a stack-based Buffer Overflow in the webmail component's 2FASetup function via an authenticated request with a long primaryEMailAddress field to the webmail/api/jsonrpc URI.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-25267?
CVE-2023-25267 has been classified as a critical vulnerability due to its potential for remote exploitation through a buffer overflow.
How do I fix CVE-2023-25267?
To fix CVE-2023-25267, upgrade GFI Kerio Connect to version 10.0.0 or later.
What components are affected by CVE-2023-25267?
CVE-2023-25267 specifically affects the webmail component of GFI Kerio Connect 9.4.1 patch 1.
Can CVE-2023-25267 be exploited without authentication?
No, CVE-2023-25267 requires an authenticated request to exploit the vulnerability.
What kind of attack does CVE-2023-25267 represent?
CVE-2023-25267 represents a stack-based buffer overflow attack, which can lead to arbitrary code execution.