WatchGuard Firebox Single Sign-On Client Denial-of-Service
An improper handling of exceptional conditions vulnerability in the WatchGuard Single Sign-On Client on Windows causes the client to crash while handling malformed commands. An attacker that has gained network access could create a denial-of-service (DoS) condition for the Single Sign-On client, preventing the computer from completing the SSO process by repeatedly issuing malformed commands.
This issue affects the Windows Single Sign-On Client: through 12.7.
An attacker must have already established network access to exploit this vulnerability. WatchGuard recommends using Windows Firewall rules to restrict TCP port 4116 network access to the Single Sign-On Client to only allow connections from the Authentication Gateway (SSO Agent).
Windows administrators can use Group Policy objects to add Windows firewall rules to their endpoints.