First published: Tue Aug 04 2020(Updated: )
ZoneAlarm Anti-Ransomware before version 1.0.713 copies files for the report from a directory with low privileges. A sophisticated timed attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on unpatched systems or using symbolic links. This allows an unprivileged user to enable escalation of privilege via local access.
Credit: cve@checkpoint.com
Affected Software | Affected Version | How to fix |
---|---|---|
Checkpoint Zonealarm Anti-ransomware | <1.0.713 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for ZoneAlarm Anti-Ransomware is CVE-2020-6012.
The severity of CVE-2020-6012 is high (7.4).
CVE-2020-6012 allows a sophisticated attacker to replace files used for reports with malicious or linked content.
ZoneAlarm Anti-Ransomware before version 1.0.713 is affected by CVE-2020-6012.
To fix CVE-2020-6012 in ZoneAlarm Anti-Ransomware, update to version 1.0.713 or later.