Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Firewalls >> ZoneAlarm Local Privilege Escalation Vulnerability


Vulnerability Assessment Details

ZoneAlarm Local Privilege Escalation Vulnerability

Vulnerability Assessment Summary
Checks version of ZoneAlarm

Detailed Explanation for this Vulnerability Assessment

Summary :

The remote Windows application is prone to a local privilege
escalation issue.

Description :

The remote host is running ZoneAlarm, a firewall for Windows.

The TrueVector service associated with the version of ZoneAlarm
installed on the remote host loads as part of its startup several
necessary DLLs without specifying their pathnames. A possible hacker with
local access can exploit this flaw to execute arbitrary programs on
the affected host with LOCAL SYSTEM rights.

See also :

http://www.securityfocus.com/archive/1/427122/30/0/threaded
http://download.zonelabs.com/bin/free/securityAlert/51.html

Solution :

Upgrade to ZoneAlarm build 6.1.744.001 or later.

Network Security Threat Level:

Medium / CVSS Base Score : 5.6
(AV:L/AC:H/Au:NR/C:C/I:C/A:C/B:N)

Networks Security ID: 17037

Vulnerability Assessment Copyright: This script is Copyright (C) 2006 Tenable Network Security

Cables, Connectors


For Cisco SFP-10G-T, Ubiquiti UF-RJ45-10G Transceiver, SFP+ to RJ45 10GBase-T picture

For Cisco SFP-10G-T, Ubiquiti UF-RJ45-10G Transceiver, SFP+ to RJ45 10GBase-T

$40.99



XGS-PON ONU SFP+ Stick MAC SC/APC 1270/1577nm -40 to 85°C 10G/10G XGSPON ONT picture

XGS-PON ONU SFP+ Stick MAC SC/APC 1270/1577nm -40 to 85°C 10G/10G XGSPON ONT

$199.99



Lifetime Warranty X520-DA2 Intel 10GB SFP+ Dual Port + 2x 10G Optics 2x 2M Cable picture

Lifetime Warranty X520-DA2 Intel 10GB SFP+ Dual Port + 2x 10G Optics 2x 2M Cable

$42.00



 Dell SFP-1G-T-WP 01M0C3 1M0C3 Transceiver SFP 1000BASE-T SFP+ NIB 1GBASE-T picture

Dell SFP-1G-T-WP 01M0C3 1M0C3 Transceiver SFP 1000BASE-T SFP+ NIB 1GBASE-T

$8.50



Lot of*5 Cisco SFP-10G-SR V03 10G 10-2415-03 21CFR Optical Transceiver picture

Lot of*5 Cisco SFP-10G-SR V03 10G 10-2415-03 21CFR Optical Transceiver

$12.16



Cisco SFP-10G-SR 10-2415-03  10 Gigabit Transceiver   LOT OF 8 picture

Cisco SFP-10G-SR 10-2415-03 10 Gigabit Transceiver LOT OF 8

$24.00



INTEL 10G SFP+ SR SFP E10GSFPSR FTLX8571D3BCV-IT For X520-DA2 X520-SR2 X710-DA2 picture

INTEL 10G SFP+ SR SFP E10GSFPSR FTLX8571D3BCV-IT For X520-DA2 X520-SR2 X710-DA2

$9.49



🔥🔥🔥Genuine Cisco SFP-10G-SR V03 10GBASE-SR SFP+ Transceiver 10-2415-03 🔥🔥🔥 picture

🔥🔥🔥Genuine Cisco SFP-10G-SR V03 10GBASE-SR SFP+ Transceiver 10-2415-03 🔥🔥🔥

$8.00



J9150D 1990-4391 HPE Aruba 10G SFP+ LC SR 300m MMF Transceiver Module US NEW picture

J9150D 1990-4391 HPE Aruba 10G SFP+ LC SR 300m MMF Transceiver Module US NEW

$50.83



Cisco SFP-10G-SR SFP Transceiver Module picture

Cisco SFP-10G-SR SFP Transceiver Module

$20.00



Discussions

No Discussions have been posted on this vulnerability.