PT-2022-25980 · Check Point · Zonealarm Extreme Security
Filip Dragović
·
Published
2022-09-27
·
Updated
2022-09-30
·
CVE-2022-41604
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Check Point ZoneAlarm Extreme Security versions prior to 15.8.211.19229
Description
The issue allows local users to escalate privileges due to weak permissions for the
%PROGRAMDATA%CheckPointZoneAlarmDataUpdates directory and a self-protection driver bypass. This bypass enables the creation of a junction directory, which can be leveraged to perform an arbitrary file move as NT AUTHORITYSYSTEM.Recommendations
For versions prior to 15.8.211.19229, update to version 15.8.211.19229 or later to resolve the issue. As a temporary workaround, consider restricting access to the
%PROGRAMDATA%CheckPointZoneAlarmDataUpdates directory to minimize the risk of exploitation.Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zonealarm Extreme Security