Filseclab Personal Firewall 3.0.0.8686 relies on the Process Environment Block (PEB) to identify a process, which allows local users to bypass the products controls on a process by spoofing the (1) ImagePathName, (2) CommandLine, and (3) WindowTitle fields in the PEB.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Antivirus_plus_firewall | Avg | 7.5.431 (including) | 7.5.431 (including) |
Comodo_personal_firewall | Comodo | 2.3.6.81 (including) | 2.3.6.81 (including) |
Personal_firewall | Filseclab | 3.0.8686 (including) | 3.0.8686 (including) |
Antihook | Infoprocess | 3.0.23 (including) | 3.0.23 (including) |
Look_n_stop | Soft4ever | 2.05p2 (including) | 2.05p2 (including) |
Sygate_personal_firewall | Symantec | 5.6.2808 (including) | 5.6.2808 (including) |