PT-2022-25980 · Check Point · Zonealarm Extreme Security

Filip Dragović

·

Published

2022-09-27

·

Updated

2022-09-30

·

CVE-2022-41604

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Check Point ZoneAlarm Extreme Security versions prior to 15.8.211.19229
Description The issue allows local users to escalate privileges due to weak permissions for the %PROGRAMDATA%CheckPointZoneAlarmDataUpdates directory and a self-protection driver bypass. This bypass enables the creation of a junction directory, which can be leveraged to perform an arbitrary file move as NT AUTHORITYSYSTEM.
Recommendations For versions prior to 15.8.211.19229, update to version 15.8.211.19229 or later to resolve the issue. As a temporary workaround, consider restricting access to the %PROGRAMDATA%CheckPointZoneAlarmDataUpdates directory to minimize the risk of exploitation.

Exploit

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2022-41604

Affected Products

Zonealarm Extreme Security