First published: Wed Apr 17 2019(Updated: )
Some of the DLLs loaded by Check Point ZoneAlarm up to 15.4.062 are taken from directories where all users have write permissions. This can allow a local attacker to replace a DLL file with a malicious one and cause Denial of Service to the client.
Credit: cve@checkpoint.com cve@checkpoint.com
Affected Software | Affected Version | How to fix |
---|---|---|
Checkpoint Zonealarm | <=15.4.062 | |
<=15.4.062 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-8453.
Check Point ZoneAlarm up to version 15.4.062 is affected.
The severity of CVE-2019-8453 is medium, with a CVSS score of 5.5.
A local attacker can exploit this vulnerability by replacing a DLL file with a malicious one, leading to a Denial of Service condition.
Yes, it is recommended to update to Check Point ZoneAlarm version 15.4.260.17960 or later to address this vulnerability.