PT-2006-4415 · Check Point Zone · Zonealarm Internet Security Suite

Publicado

2006-07-13

·

Atualizado

2018-10-18

·

CVE-2006-3540

CVSS v2.0

4.9

Média

VetorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Check Point Zone Labs ZoneAlarm Internet Security Suite versions 6.1.737.000, 6.5.722.000
Description The issue arises from improper validation of function calls, specifically RegSaveKey, RegRestoreKey, and RegDeleteKey, which can be exploited by local users to cause a denial of service, resulting in a system crash. This is achieved through a specific combination of these function calls with an argument related to HKEY LOCAL MACHINESYSTEMCurrentControlSetServicesVETFDDNTEnum.
Recommendations For version 6.1.737.000, consider disabling the RegSaveKey, RegRestoreKey, and RegDeleteKey functions as a temporary workaround until a patch is available. For version 6.5.722.000, restrict access to the HKEY LOCAL MACHINESYSTEMCurrentControlSetServicesVETFDDNTEnum registry key to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-3540

Produtos afetados

Zonealarm Internet Security Suite