CVE-2003-1309: Critical severity Zonelabs ZoneAlarm vulnerability
The DeviceIoControl function in the TrueVector Device Driver (VSDATANT) in ZoneAlarm before 3.7.211, Pro before 4.0.146.029, and Plus before 4.0.146.029 allows local users to gain privileges via certain signals (aka "Device Driver Attack").
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2003-1309?
The severity of CVE-2003-1309 is considered medium, as it allows local users to gain elevated privileges.
How do I fix CVE-2003-1309?
To fix CVE-2003-1309, update to the latest version of ZoneAlarm beyond 3.7.211, Pro 4.0.146.029, or Plus 4.0.146.029.
Which versions of ZoneAlarm are affected by CVE-2003-1309?
CVE-2003-1309 affects ZoneAlarm versions 3.7.211 and below, and Pro and Plus versions prior to 4.0.146.029.
What is the impact of CVE-2003-1309 on my system?
The impact of CVE-2003-1309 is that it may allow local users to exploit the system to gain unauthorized privileges.
Is there a workaround for CVE-2003-1309?
A workaround for CVE-2003-1309 is to restrict local user access and monitor system signals to prevent exploitation until a patch is applied.