CVE-2019-8452
Summary
| CVE | CVE-2019-8452 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-04-22 22:29:00 UTC |
| Updated | 2020-10-22 17:17:00 UTC |
| Description | A hard-link created from log file archive of Check Point ZoneAlarm up to 15.4.062 or Check Point Endpoint Security client for Windows before E80.96 to any file on the system will get its permission changed so that all users can access that linked file. Doing this on files with limited access gains the local attacker higher privileges to the file. |
Risk And Classification
Problem Types: CWE-59
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Checkpoint | Endpoint Security | All | All | All | All |
| Application | Checkpoint | Endpoint Security | All | All | All | All |
| Application | Checkpoint | Zonealarm | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ZoneAlarm Free Antivirus + Firewall release history official page | ZoneAlarm | MISC | www.zonealarm.com | Vendor Advisory |
| Enterprise Endpoint Security E80.96 Windows Clients | CONFIRM | supportcenter.us.checkpoint.com | Vendor Advisory |
| CheckPoint Endpoint Security Client / ZoneAlarm Privilege Escalation ≈ Packet Storm | MISC | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.