Privilege Escalation Vulnerability in Check Point ZoneAlarm
CVE-2022-23743
7.8HIGH
What is CVE-2022-23743?
The vulnerability in Check Point ZoneAlarm allows local actors to escalate their privileges during the software upgrade process. This flaw is exacerbated by inadequate permissions in the ProgramData\CheckPoint\ZoneAlarm\Data\Updates directory, enabling attackers to execute arbitrary file writes. Consequently, attackers can gain elevated privileges, allowing them to execute code with local system rights, which can compromise the security of the affected system.
Affected Version(s)
ZoneAlarm. before v15.8.211.192119