CVE-2007-2174: High severity Checkpoint ZoneAlarm vulnerability
Published Apr 24, 2007
·Updated
The IOCTL handling in srescan.sys in the ZoneAlarm Spyware Removal Engine (SRE) in Check Point ZoneAlarm before 5.0.156.0 allows local users to execute arbitrary code via certain IOCTL lrp parameter addresses.
Affected Software
1 affected component
Checkpoint ZoneAlarm<=5.0.63.0
Remediation
Patch Available
Event History
Apr 24, 2007
CVE Published
04:19 PM
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2174?
CVE-2007-2174 is classified as a high severity vulnerability that allows local users to execute arbitrary code.
2
How do I fix CVE-2007-2174?
To fix CVE-2007-2174, users should upgrade their Check Point ZoneAlarm software to version 5.0.156.0 or later.
3
Which versions of Check Point ZoneAlarm are affected by CVE-2007-2174?
CVE-2007-2174 affects Check Point ZoneAlarm versions prior to 5.0.156.0.
4
Is CVE-2007-2174 exploitable by remote users?
No, CVE-2007-2174 can only be exploited by local users with access to the system.
5
What component of Check Point ZoneAlarm does CVE-2007-2174 affect?
CVE-2007-2174 affects the IOCTL handling in the srescan.sys component of the ZoneAlarm Spyware Removal Engine.