CVE-2018-8790Incorrect Authorization in Checkpoint Zonealarm

Severity
7.8HIGHNVD
EPSS
0.1%
top 81.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 1
Latest updateMay 13

Description

Check Point ZoneAlarm version 15.3.064.17729 and below expose a WCF service that can allow a local low privileged user to execute arbitrary code as SYSTEM.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

NVDcheckpoint/zonealarm15.3.064.17729
CVEListV5check_point_software_technologies_ltd/zonealarmprior to version 15.3.064.17729

🔴Vulnerability Details

2
GHSA
GHSA-jhvm-cvpr-9jq3: Check Point ZoneAlarm version 152022-05-13
CVEList
CVE-2018-8790: Check Point ZoneAlarm version 152019-03-01
CVE-2018-8790 — Incorrect Authorization in Checkpoint | cvebase