PT-2007-3515 · Check Point · Zonealarm

Published

2007-04-24

·

Updated

2018-10-16

·

CVE-2007-2174

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Check Point ZoneAlarm versions prior to 5.0.156.0
Description The issue concerns the IOCTL handling in srescan.sys within the ZoneAlarm Spyware Removal Engine (SRE), allowing local users to execute arbitrary code via certain IOCTL lrp parameter addresses.
Recommendations For versions prior to 5.0.156.0, update to version 5.0.156.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the srescan.sys driver to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-2174

Affected Products

Zonealarm