FYI…

- http://www.us-cert.gov/cas/bulletins/SB05-320.html#win5
WinRoute Firewall prior to 6.1.3
A vulnerability has been reported in WinRoute Firewall that could let remote malicious users bypass security restrictions. Specifically, formerly authenticated users may be able to authenticate with disabled accounts.

>>> Upgrade to version 6.1.3: http://www.kerio.com/kwf_download.html
(Kerio WinRoute Firewall / Current version: 6.1.3 Patch 1 / Release date: November 16, 2005)

There is no exploit code required.

- http://securitytracker.com/alerts/2005/Nov/1015194.html

:ph34r: