Wh04m1001/ZoneAlarmEoP

Wh04m1001/ZoneAlarmEoP

Releases0
Stars26
Exploit for Arbitrary File Move vulnerability in ZoneAlarm AV

CVE History

CVEPublishedCVSS v3CVSS v2
8.8 HIGH

Check Point ZoneAlarm Extreme Security before 15.8.211.19229 allows local users to escalate privileges. This occurs because of weak permissions for the %PROGRAMDATA%\CheckPoint\ZoneAlarm\Data\Updates directory, and a self-protection driver bypass that allows creation of a junction directory. This can be leveraged to perform an arbitrary file move as NT AUTHORITY\SYSTEM.