CVE-2024-52875 – Multiple vulnerabilities enable 1-Click RCE at Kerio Control
A critical vulnerability, CVE-2024-52875, has been identified in Kerio Control versions 9.2.5 through 9.4.5 including, affecting the security of systems using these versions. This vulnerability arises from two distinct issues: CRLF injection and Reflected Cross-Site Scripting (XSS), both caused by improper input sanitization on specific web pages. CRLF injection allows attackers to manipulate HTTP headers, which can lead to various response-splitting attacks, while XSS enables malicious scripts to execute in the context of a user’s browser. When these two issues are exploited in combination, they provide attackers with a pathway to escalate privileges and achieve 1 click remote code execution (RCE), significantly increasing the severity and impact of the vulnerability.
References: