Lucene search

K
nvd[email protected]NVD:CVE-2022-41604
HistorySep 27, 2022 - 11:15 p.m.

CVE-2022-41604

2022-09-2723:15:17
CWE-269
web.nvd.nist.gov
2
check point zonealarm
extreme security
privilege escalation

CVSS3

8.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

EPSS

0

Percentile

5.1%

Check Point ZoneAlarm Extreme Security before 15.8.211.19229 allows local users to escalate privileges. This occurs because of weak permissions for the %PROGRAMDATA%\CheckPoint\ZoneAlarm\Data\Updates directory, and a self-protection driver bypass that allows creation of a junction directory. This can be leveraged to perform an arbitrary file move as NT AUTHORITY\SYSTEM.

Affected configurations

Nvd
Node
checkpointzonealarmRange<15.8.211.19229
VendorProductVersionCPE
checkpointzonealarm*cpe:2.3:a:checkpoint:zonealarm:*:*:*:*:*:*:*:*

CVSS3

8.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

EPSS

0

Percentile

5.1%

Related for NVD:CVE-2022-41604