Privilege Escalation Vulnerability in Check Point ZoneAlarm and Identity Agents
CVE-2024-24910

7.3HIGH

What is CVE-2024-24910?

A local attacker can exploit a security vulnerability that allows for privilege escalation on the affected products, including Check Point ZoneAlarm Extreme Security and Identity Agent for Windows. In order to successfully execute the exploit, the attacker must initially gain the ability to execute local privileged code on the targeted system. This vulnerability can potentially lead to unauthorized access and manipulation of system resources by local attackers.

Affected Version(s)

ZoneAlarmExtremeSecurityNextGen,IdentityAgentforWindows,IdentityAgentforWindowsTerminalServer ZoneAlarmExtremeSecurityNextGen-versionslowerthan4.2.7,IdentityAgentforWindows-versionslowerthanR81.070.0000,IdentityAgentforWindowsTerminalServer-versionslowerthanR81.070.0000

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.
CVE-2024-24910 : Privilege Escalation Vulnerability in Check Point ZoneAlarm and Identity Agents