CVE-2003-0220

Kerio Personal Firewall <2.1.4 - RCE

Title source: llm

Description

Buffer overflow in the administrator authentication process for Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute arbitrary code via a handshake packet.

Exploits (6)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16465
exploitdb WORKING POC VERIFIED
by y0 · remotewindows
https://www.exploit-db.com/exploits/1537
exploitdb WORKING POC VERIFIED
by Burebista · cremotewindows
https://www.exploit-db.com/exploits/28
exploitdb WORKING POC VERIFIED
by ThreaT · cremotewindows
https://www.exploit-db.com/exploits/22418
exploitdb WORKING POC VERIFIED
by Core Security · pythondoswindows
https://www.exploit-db.com/exploits/22417
metasploit WORKING POC NORMAL
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/firewall/kerio_auth.rb

Scores

EPSS 0.8050
EPSS Percentile 99.1%

Details

Status published
Products (5)
kerio/personal_firewall_2 2.1
kerio/personal_firewall_2 2.1.1
kerio/personal_firewall_2 2.1.2
kerio/personal_firewall_2 2.1.3
kerio/personal_firewall_2 2.1.4
Published May 12, 2003
Tracked Since Feb 18, 2026