CVE-2019-8453

Some of the DLLs loaded by Check Point ZoneAlarm up to 15.4.062 are taken from directories where all users have write permissions. This can allow a local attacker to replace a DLL file with a malicious one and cause Denial of Service to the client.
Configurations

Configuration 1 (hide)

cpe:2.3:a:checkpoint:zonealarm:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:49

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/108029 - () http://www.securityfocus.com/bid/108029 -
References () https://www.zonealarm.com/software/release-history/zafavfw.html#15.4.260.17960 - Vendor Advisory () https://www.zonealarm.com/software/release-history/zafavfw.html#15.4.260.17960 - Vendor Advisory

Information

Published : 2019-04-17 15:29

Updated : 2024-11-21 04:49


NVD link : CVE-2019-8453

Mitre link : CVE-2019-8453

CVE.ORG link : CVE-2019-8453


JSON object : View

Products Affected

checkpoint

  • zonealarm
CWE
CWE-114

Process Control

CWE-426

Untrusted Search Path