CVE-2019-8455: High severity alarm vulnerability
A hard-link created from the log file of Check Point ZoneAlarm up to 15.4.062 to any file on the system will get its permission changed so that all users can access that linked file. Doing this on files with limited access gains the local attacker higher privileges to the file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-8455?
CVE-2019-8455 is a vulnerability found in Check Point ZoneAlarm up to version 15.4.062, which allows a local attacker to gain higher privileges by creating a hard link from a log file to another file on the system.
How does CVE-2019-8455 affect Check Point ZoneAlarm?
CVE-2019-8455 allows a local attacker to change the permissions of a linked file created from a log file, gaining higher privileges on files with limited access.
What is the severity of CVE-2019-8455?
CVE-2019-8455 has a severity rating of 7.1 (high).
How can I fix CVE-2019-8455?
To fix CVE-2019-8455, update your Check Point ZoneAlarm software to version 15.4.062 or later.
Where can I find more information about CVE-2019-8455?
You can find more information about CVE-2019-8455 on the following references: [http://www.securityfocus.com/bid/108029](http://www.securityfocus.com/bid/108029) and [https://www.zonealarm.com/software/release-history/zafavfw.html#15.4.260.17960](https://www.zonealarm.com/software/release-history/zafavfw.html#15.4.260.17960)