CVE-2020-6012

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
04/08/2020
Last modified:
31/01/2023

Description

ZoneAlarm Anti-Ransomware before version 1.0.713 copies files for the report from a directory with low privileges. A sophisticated timed attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on unpatched systems or using symbolic links. This allows an unprivileged user to enable escalation of privilege via local access.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:checkpoint:zonealarm_anti-ransomware:*:*:*:*:*:*:*:* 1.0.713 (excluding)