CVE-2018-8790

Check Point ZoneAlarm version 15.3.064.17729 and below expose a WCF service that can allow a local low privileged user to execute arbitrary code as SYSTEM.
Configurations

Configuration 1 (hide)

cpe:2.3:a:checkpoint:zonealarm:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:14

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/107254 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/107254 - Third Party Advisory, VDB Entry
References () https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk142952 - Vendor Advisory () https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk142952 - Vendor Advisory
References () https://www.zonealarm.com/software/release-history/zafavfw.html#15.4.062.17802 - Release Notes, Vendor Advisory () https://www.zonealarm.com/software/release-history/zafavfw.html#15.4.062.17802 - Release Notes, Vendor Advisory
References () https://www.zonealarm.com/software/release-history/zafree.html#15.4.062.17802 - Release Notes, Vendor Advisory () https://www.zonealarm.com/software/release-history/zafree.html#15.4.062.17802 - Release Notes, Vendor Advisory

Information

Published : 2019-03-01 16:29

Updated : 2024-11-21 04:14


NVD link : CVE-2018-8790

Mitre link : CVE-2018-8790

CVE.ORG link : CVE-2018-8790


JSON object : View

Products Affected

checkpoint

  • zonealarm
CWE
CWE-863

Incorrect Authorization

NVD-CWE-noinfo