AI
AI

Over 12,000 KerioControl Firewalls Vulnerable to RCE Attacks Due to Ongoing Exploits

Photo credit: www.csoonline.com

The Flaw Enables One-Click RCE

A serious vulnerability has been discovered in Kerio Control, which when combined with an older weakness, can facilitate a one-click Remote Code Execution (RCE) attack. This vulnerability has been present for almost seven years and affects versions ranging from 9.2.5, introduced in 2018, to 9.4.5.

Research conducted by cybersecurity expert Romano has demonstrated that the exploit involves injecting Base64-encoded payloads, which can manipulate HTTP responses to introduce harmful headers or illicit content. This creates the possibility for an HTTP response splitting attack, potentially leading to reflected Cross-Site Scripting (XSS) that allows for remote code execution.

The issue has been addressed in the recent patches for versions 9.4.5 Patch1 and Patch2, released on December 19 and January 31, respectively. These updates not only fix the vulnerability but also provide additional security enhancements. GFI Software has urged system administrators to implement these patches without delay to safeguard their systems against potential exploits. GFI Kerio Control is widely utilized across various sectors, including notable organizations such as McDonald’s and Luxury Motor Yacht Lotus, with its presence spanning hundreds of thousands of active installations worldwide.

Source
www.csoonline.com

Related by category

Cybersecurity Leaders Condemn ‘Political Persecution’ of Chris Krebs in Letter to the President

Photo credit: www.csoonline.com In November 2018, President Trump appointed Chris...

Broadcom-Supported SAN Devices Vulnerable to Code Injection Attacks Due to Critical Fabric OS Flaw

Photo credit: www.csoonline.com Critical Vulnerability Found in Broadcom’s Brocade Fabric...

Cyberattack on berlin.de | CSO Online

Photo credit: www.csoonline.com Cyberangriff auf Berlins Info- und Serviceportal berlin.de Ende...

Latest news

Gifting System Update, Major Yoru Nerf, and Additional Changes

Photo credit: dotesports.com VALORANT Patch 10.08 marks the introduction of...

Understanding the Ghorman Massacre: An Overview

Photo credit: movieweb.com Warning: This article contains spoilers for Andor...

Why I’m Grateful Blue Bloods Was Canceled Before Season 15

Photo credit: www.tvfanatic.com As a devoted fan of Blue Bloods,...

Breaking news