CVE-2007-2083: Medium severity Zonelabs ZoneAlarm vulnerability
vsdatant.sys in Check Point Zone Labs ZoneAlarm Pro before 7.0.302.000 does not validate certain arguments before being passed to hooked SSDT function handlers, which allows local users to cause a denial of service (system crash) or possibly execute arbitrary code via crafted arguments to the (1) NtCreateKey and (2) NtDeleteFile functions.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2083?
CVE-2007-2083 has a severity rating that indicates a vulnerability allowing denial of service and potential arbitrary code execution.
How do I fix CVE-2007-2083?
To fix CVE-2007-2083, upgrade to Check Point Zone Labs ZoneAlarm Pro version 7.0.302.000 or later.
What systems are affected by CVE-2007-2083?
CVE-2007-2083 affects Check Point Zone Labs ZoneAlarm Pro versions prior to 7.0.302.000.
What kind of attacks can be executed through CVE-2007-2083?
CVE-2007-2083 can be exploited to cause a denial of service or possibly execute arbitrary code.
Who can exploit CVE-2007-2083?
CVE-2007-2083 can be exploited by local users of the affected systems.