SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-8453

This can allow a local attacker to replace a DLL file with a malicious one and cause Denial of Service to the client.

MEDIUM 5.5EPSS 0.32%

Does this matter?

Lower severity and a low EPSS score (0.32%). Track it; it rarely justifies an emergency change on its own.

Description

Some of the DLLs loaded by Check Point ZoneAlarm up to 15.4.062 are taken from directories where all users have write permissions. This can allow a local attacker to replace a DLL file with a malicious one and cause Denial of Service to the client.

CVSS 3.0
5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS
0.32% probability · 25th percentile
CISA KEV
Not listed
Weakness
CWE-114, CWE-426
Affected
checkpoint/zonealarm
Source
cve@checkpoint.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.