CVE-2019-8453

Severity CVSS v4.0:
Pending analysis
Type:
CWE-426 Untrusted Search Path
Publication date:
17/04/2019
Last modified:
23/04/2019

Description

Some of the DLLs loaded by Check Point ZoneAlarm up to 15.4.062 are taken from directories where all users have write permissions. This can allow a local attacker to replace a DLL file with a malicious one and cause Denial of Service to the client.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:checkpoint:zonealarm:*:*:*:*:*:*:*:* 15.4.062 (including)