VulnerabilityModified
CVE-2019-8453
This can allow a local attacker to replace a DLL file with a malicious one and cause Denial of Service to the client.
MEDIUM 5.5EPSS 0.32%
Does this matter?
Lower severity and a low EPSS score (0.32%). Track it; it rarely justifies an emergency change on its own.
Description
Some of the DLLs loaded by Check Point ZoneAlarm up to 15.4.062 are taken from directories where all users have write permissions. This can allow a local attacker to replace a DLL file with a malicious one and cause Denial of Service to the client.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.32% probability · 25th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-114, CWE-426
- Affected
- checkpoint/zonealarm
- Source
- cve@checkpoint.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.