CVE-2005-3286

medium

Description

The FWDRV driver in Kerio Personal Firewall 4.2 and Server Firewall 1.1.1 allows local users to cause a denial of service (crash) by setting the PAGE_NOACCESS or PAGE_GUARD protection on the Page Environment Block (PEB), which triggers an exception, aka the "PEB lockout vulnerability."

References

http://www.securityfocus.com/bid/15094

http://www.osvdb.org/19961

http://www.kerio.com/security_advisory.html

http://securityreason.com/securityalert/78

http://secunia.com/advisories/17155

http://seclists.org/bugtraq/2005/Oct/166

http://pb.specialised.info/all/adv/kerio-fwdrv-dos-adv.txt

http://lists.grok.org.uk/pipermail/full-disclosure/2005-October/037958.html

Details

Source: Mitre, NVD

Published: 2005-10-23

Updated: 2026-06-16

Risk Information

CVSS v2

Base Score: 2.1

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:P

Severity: Low

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00096