Sunbelt Kerio Personal Firewall 4.3.426 - CreateRemoteThread Denial of Service

Related Vulnerabilities: CVE-2006-3787  
Publish Date: 15 Jul 2006
                							

                source: http://www.securityfocus.com/bid/18996/info

Sunbelt Kerio Personal Firewall is prone to a denial-of-service vulnerability. This issue can occur when a program calls the 'CreateRemoteThread' Windows API call.

Exploitation of this vulnerability could cause the firewall application to crash. This could expose the computer to further attacks.

The individual who discovered this vulnerability claims to have tested it on Sunbelt Kerio Personal Firewall versions 4.3.246 and 4.2.3.912. They were unable to reproduce the vulnerability on version 4.2.3.912, which is an older release. The vulnerable functionality may have been introduced at some point after the 4.2.3.912 release, but this has not been confirmed.

https://github.com/offensive-security/exploitdb-bin-sploits/raw/master/bin-sploits/28228.zip