PT-2022-16245 · Check Point · Zonealarm

Published

2022-05-11

·

Updated

2023-02-10

·

CVE-2022-23743

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Check Point ZoneAlarm versions prior to 15.8.200.19118
Description The issue allows a local actor to escalate privileges during the upgrade process. Additionally, weak permissions in the ProgramDataCheckPointZoneAlarmDataUpdates directory enable a local attacker to execute an arbitrary file write, leading to code execution as the local system.
Recommendations For versions prior to 15.8.200.19118, update to version 15.8.200.19118 or later to resolve the issue. As a temporary workaround, consider restricting access to the ProgramDataCheckPointZoneAlarmDataUpdates directory to minimize the risk of exploitation.

Fix

Improper Privilege Management

Incorrect Permission

Weakness Enumeration

Related Identifiers

CVE-2022-23743

Affected Products

Zonealarm