CVE-2022-41604

HIGH

Check Point ZoneAlarm Extreme Security <15.8.211.19229 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Check Point ZoneAlarm Extreme Security before 15.8.211.19229 allows local users to escalate privileges. This occurs because of weak permissions for the %PROGRAMDATA%\CheckPoint\ZoneAlarm\Data\Updates directory, and a self-protection driver bypass that allows creation of a junction directory. This can be leveraged to perform an arbitrary file move as NT AUTHORITY\SYSTEM.

References (3)

Core 3
Core References
Exploit, Release Notes, Third Party Advisory x_refsource_misc
https://github.com/Wh04m1001/ZoneAlarmEoP
Release Notes, Vendor Advisory x_refsource_misc
https://www.zonealarm.com/software/extreme-security/release-history

Scores

CVSS v3 8.8
EPSS 0.0004
EPSS Percentile 12.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (1)
checkpoint/zonealarm < 15.8.211.19229
Published Sep 27, 2022
Tracked Since Feb 18, 2026