CVE-2006-3540: Medium severity ZoneLabs Zonealarm Security Suite vulnerability
Check Point Zone Labs ZoneAlarm Internet Security Suite 6.5.722.000, 6.1.737.000, and possibly other versions do not properly validate RegSaveKey, RegRestoreKey, and RegDeleteKey function calls, which allows local users to cause a denial of service (system crash) via a certain combination of these function calls with an HKEYLOCALMACHINE\SYSTEM\CurrentControlSet\Services\VETFDDNT\Enum argument.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3540?
CVE-2006-3540 has been classified as a medium severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2006-3540?
To mitigate CVE-2006-3540, users should update to the latest version of Check Point Zone Labs ZoneAlarm Internet Security Suite.
What versions are affected by CVE-2006-3540?
CVE-2006-3540 affects Check Point Zone Labs ZoneAlarm Internet Security Suite versions 6.1.737.000 and 6.5.722.000.
What kind of exploit does CVE-2006-3540 involve?
CVE-2006-3540 involves local users exploiting improper validation of RegSaveKey, RegRestoreKey, and RegDeleteKey function calls.
Can CVE-2006-3540 lead to system instability?
Yes, CVE-2006-3540 can cause a denial of service, which may result in system crashes.