HomeSecurityRCE vulnerability in Kerio Control allows root access to firewall

RCE vulnerability in Kerio Control allows root access to firewall

Researchers have identified a set of critical vulnerabilities in Kerio Control, a widely used Unified Threat Management (UTM) developed by GFI Software, which can be exploited in attacks.

See also: RCE vulnerability in Apache Struts 2 puts servers at risk

Kerio RCE attack

The impact is severe, potentially allowing attackers to escalate low-severity issues to attacks , which provide root access to the firewall system.

These RCE flaws in Kerio, which are collectively tracked as CVE-2024-52875 (or KIS-2024-07), have been present in the software for nearly seven years and affect versions from 9.2.5 (released in March 2018) to 9.4.5.

The vulnerabilities stem from a CRLF Injection in several pages of the web interface, including:

  • /nonauth/addCertException.cs
  • /nonauth/guestConfirm.cs
  • /nonauth/expiration.cs

See also: Qlik Sense Enterprise vulnerability allows RCE execution

The issue concerns improper sanitization of user input passed through the dest GET, which is used to create an HTTP header in a 302 Found response.

RCE vulnerability in Kerio Control allows root access to firewall

By inserting Base64 -encoded payloads in the dest parameter, attackers can manipulate the HTTP response to inject arbitrary HTTP headers and even custom HTML content . Initially classified as a “Low” severity issue due to the need for user interaction, further analysis revealed that the vulnerabilities could be escalated to a high severity (8.8). By exploiting a nine-year-old exploit in Kerio Control’s upgrade functionality, attackers can deliver a Remote Command Execution (RCE) payload with a single click.

See also: GitHub CLI RCE vulnerability allows execution of malicious commands

A Remote Code Execution (RCE) vulnerability, such as the one in Kerio Control, is a critical cybersecurity vulnerability that allows attackers to execute arbitrary code on a remote system. This type of attack typically exploits flaws in software, such as inadequate login validation or unpatched vulnerabilities, allowing unauthorized users to gain control of the targeted system. RCE attacks can lead to significant consequences, such as data breaches, service disruption, or the deployment of malware such as ransomware. To mitigate the risk of RCE attacks, organizations are encouraged to regularly update their software, implement strong security practices, and perform comprehensive vulnerability assessments.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS