CVE-2019-8453: Medium severity alarm vulnerability
Published Apr 17, 2019
·Updated
Some of the DLLs loaded by Check Point ZoneAlarm up to 15.4.062 are taken from directories where all users have write permissions. This can allow a local attacker to replace a DLL file with a malicious one and cause Denial of Service to the client.
Affected Software
1 affected component
Checkpoint ZoneAlarm<=15.4.062
Event History
Apr 17, 2019
CVE Published
via MITRE·02:06 PM
Data Sourced
via MITRE·02:06 PM
DescriptionWeakness
Data Sourced
via NVD·03:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2019-8453.
2
Which software is affected by this vulnerability?
Check Point ZoneAlarm up to version 15.4.062 is affected.
3
What is the severity of CVE-2019-8453?
The severity of CVE-2019-8453 is medium, with a CVSS score of 5.5.
4
How can a local attacker exploit this vulnerability?
A local attacker can exploit this vulnerability by replacing a DLL file with a malicious one, leading to a Denial of Service condition.
5
Are there any known fixes for this vulnerability?
Yes, it is recommended to update to Check Point ZoneAlarm version 15.4.260.17960 or later to address this vulnerability.