CVE-2023-25267 | GFI Kerio Connect 9.4.1 Patch 1 2FASetup webmail/api/jsonrpc primaryEMailAddress stack-based overflow (EUVD-2023-29229)
A vulnerability, which was classified as critical, has been found in GFI Kerio Connect 9.4.1 Patch 1. This issue affects some unknown processing of the file webmail/api/jsonrpc of the component 2FASetup. Performing manipulation of the argument primaryEMailAddress results in stack-based buffer overflow.
This vulnerability is identified as CVE-2023-25267. The attack can only be performed from the local network. There is not any exploit available.
It is advisable to upgrade the affected component.