icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons_061

Kerio MailServer / Connect < 7.0.1 Administration Console File Disclosure and File Corruption Vulnerability

Medium

Synopsis

The remote mail server is vulnerable to a file disclosure and corruption vulnerability.

Description

Versions of Kerio Mail Server / Connect earlier than 7.0.1 are potentially affected by a file disclosure and corruption vulnerability. An attacker, with full administrative rights, can modify the administrative console to change the product configuration to read or corrupt arbitrary files on the server.

Solution

Upgrade to Kerio Connect 7.0.1 or later.