ZDI-23-1764: Check Point ZoneAlarm Extreme Security Link Following Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Check Point ZoneAlarm Extreme Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2023-28134.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-1764?
The severity of ZDI-23-1764 is critical because it allows local attackers to escalate privileges on affected installations.
How do I fix ZDI-23-1764?
To fix ZDI-23-1764, users should apply the latest security patch provided by Check Point for ZoneAlarm Extreme Security.
Who is affected by ZDI-23-1764?
ZDI-23-1764 affects users of Check Point ZoneAlarm Extreme Security on systems that allow low-privileged code execution.
What type of attack does ZDI-23-1764 involve?
ZDI-23-1764 involves local privilege escalation attacks where an attacker needs to execute low-privileged code.
Is there a workaround for ZDI-23-1764?
Currently, there is no known workaround for ZDI-23-1764 other than applying the security patch as soon as it is available.