Check Point ZoneAlarm Extreme Security before 15.8.211.19229 allows local users to escalate privileges. This occurs because of weak permissions for the %PROGRAMDATA%\CheckPoint\ZoneAlarm\Data\Updates directory, and a self-protection driver bypass that allows creation of a junction directory. This can be leveraged to perform an arbitrary file move as NT AUTHORITY\SYSTEM.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 22 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-05-22T13:52:43.192Z
Reserved: 2022-09-27T00:00:00.000Z
Link: CVE-2022-41604
Updated: 2024-08-03T12:49:43.364Z
Status : Modified
Published: 2022-09-27T23:15:17.263
Modified: 2025-05-22T14:16:01.390
Link: CVE-2022-41604
No data.
OpenCVE Enrichment
No data.
Weaknesses