Vulnerability Description
Check Point ZoneAlarm before version 15.8.200.19118 allows a local actor to escalate privileges during the upgrade process. In addition, weak permissions in the ProgramData\CheckPoint\ZoneAlarm\Data\Updates directory allow a local attacker the ability to execute an arbitrary file write, leading to execution of code as local system, in ZoneAlarm versions before v15.8.211.192119
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Checkpoint | Zonealarm | < 15.8.211.192119 |
Related Weaknesses (CWE)
References
- https://www.zonealarm.com/software/extreme-security/release-historyRelease NotesVendor Advisory
- https://www.zonealarm.com/software/extreme-security/release-historyRelease NotesVendor Advisory
FAQ
What is CVE-2022-23743?
CVE-2022-23743 is a vulnerability with a CVSS score of 7.8 (HIGH). Check Point ZoneAlarm before version 15.8.200.19118 allows a local actor to escalate privileges during the upgrade process. In addition, weak permissions in the ProgramData\CheckPoint\ZoneAlarm\Data\U...
How severe is CVE-2022-23743?
CVE-2022-23743 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-23743?
Check the references section above for vendor advisories and patch information. Affected products include: Checkpoint Zonealarm.