Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5prc-43fj-m4f2

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A hard-link created from log file archive of Check Point ZoneAlarm up to 15.4.062 or Check Point Endpoint Security client for Windows before E80.96 to any file on the system will get its permission changed so that all users can access that linked file. Doing this on files with limited access gains the local attacker higher privileges to the file.

A hard-link created from log file archive of Check Point ZoneAlarm up to 15.4.062 or Check Point Endpoint Security client for Windows before E80.96 to any file on the system will get its permission changed so that all users can access that linked file. Doing this on files with limited access gains the local attacker higher privileges to the file.

EPSS

Процентиль: 44%
0.00219
Низкий

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 7.8
nvd
почти 7 лет назад

A hard-link created from log file archive of Check Point ZoneAlarm up to 15.4.062 or Check Point Endpoint Security client for Windows before E80.96 to any file on the system will get its permission changed so that all users can access that linked file. Doing this on files with limited access gains the local attacker higher privileges to the file.

CVSS3: 7.8
fstec
почти 7 лет назад

Уязвимость клиента комплексной защиты конечных точек сети Check Point Endpoint Security Initial Client для Windows и межсетевого экрана ZoneAlarm, связанная с ошибками обработки разрешений, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 44%
0.00219
Низкий

Дефекты

CWE-59