Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
41 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.40% | — | Checkpoint Zonealarm Extreme Security Nextgen | 22/11/2024 | 17/6/2026 | Check Point ZoneAlarm Extreme Security Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Check Point ZoneAlarm Extreme Security. An attacker must first obtain the ability to execute low-privileged code on the target… | |
| Analizada | Alta (7.3) | 0.15% | — | Checkpoint Identity AgentCheckpoint Zonealarm Extreme Security Nextgen | 18/4/2024 | 17/6/2026 | A local attacker can erscalate privileges on affected Check Point ZoneAlarm ExtremeSecurity NextGen, Identity Agent for Windows, and Identity Agent for Windows Terminal Server. To exploit this vulnerability, an attacker must first obtain the ability to execute local privileged code on the target system. | |
| Modificada | Alta (8.8) | 0.62% | — | Checkpoint Zonealarm | 27/9/2022 | 17/6/2026 | Check Point ZoneAlarm Extreme Security before 15.8.211.19229 allows local users to escalate privileges. This occurs because of weak permissions for the %PROGRAMDATA%\CheckPoint\ZoneAlarm\Data\Updates directory, and a self-protection driver bypass that allows creation of a junction directory. This can be leveraged to… | |
| Modificada | Alta (7.8) | 0.42% | — | Checkpoint Zonealarm | 11/5/2022 | 17/6/2026 | Check Point ZoneAlarm before version 15.8.200.19118 allows a local actor to escalate privileges during the upgrade process. In addition, weak permissions in the ProgramData\CheckPoint\ZoneAlarm\Data\Updates directory allow a local attacker the ability to execute an arbitrary file write, leading to execution of code as… | |
| Modificada | Alta (7.8) | 0.34% | — | Checkpoint Zonealarm | 27/10/2020 | 17/6/2026 | Check Point ZoneAlarm before version 15.8.139.18543 allows a local actor to escalate privileges while restoring files in Anti-Ransomware. | |
| Modificada | Media (5.5) | 0.31% | — | Checkpoint Zonealarm | 27/10/2020 | 17/6/2026 | Check Point ZoneAlarm before version 15.8.139.18543 allows a local actor to delete arbitrary files while restoring files in Anti-Ransomware. | |
| Modificada | Alta (7.4) | 0.52% | — | Checkpoint Zonealarm Anti-ransomware | 4/8/2020 | 17/6/2026 | ZoneAlarm Anti-Ransomware before version 1.0.713 copies files for the report from a directory with low privileges. A sophisticated timed attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on unpatched systems or using symbolic links. This allows an unprivileged user to… | |
| Modificada | Alta (8.8) | 1.6% | — | Checkpoint Zonealarm Extreme Security | 6/7/2020 | 17/6/2026 | ZoneAlarm Firewall and Antivirus products before version 15.8.109.18436 allow an attacker who already has access to the system to execute code at elevated privileges through a combination of file permission manipulation and exploitation of Windows CVE-2020-00896 on unpatched systems. | |
| Modificada | Alta (7.8) | 1.0% | — | Checkpoint Endpoint SecurityCheckpoint Zonealarm | 22/4/2019 | 17/6/2026 | A hard-link created from log file archive of Check Point ZoneAlarm up to 15.4.062 or Check Point Endpoint Security client for Windows before E80.96 to any file on the system will get its permission changed so that all users can access that linked file. Doing this on files with limited access gains the local attacker… | |
| Modificada | Alta (7.1) | 0.39% | — | Checkpoint Zonealarm | 17/4/2019 | 17/6/2026 | A hard-link created from the log file of Check Point ZoneAlarm up to 15.4.062 to any file on the system will get its permission changed so that all users can access that linked file. Doing this on files with limited access gains the local attacker higher privileges to the file. | |
| Modificada | Media (5.5) | 0.32% | — | Checkpoint Zonealarm | 17/4/2019 | 17/6/2026 | Some of the DLLs loaded by Check Point ZoneAlarm up to 15.4.062 are taken from directories where all users have write permissions. This can allow a local attacker to replace a DLL file with a malicious one and cause Denial of Service to the client. | |
| Modificada | Alta (7.8) | 0.39% | — | Checkpoint Zonealarm | 1/3/2019 | 17/6/2026 | Check Point ZoneAlarm version 15.3.064.17729 and below expose a WCF service that can allow a local low privileged user to execute arbitrary code as SYSTEM. | |
| Modificada | Media (6.2) | 0.29% | — | Checkpoint Zonealarm Extreme Security | 25/8/2012 | 16/6/2026 | Race condition in ZoneAlarm Extreme Security 9.1.507.000 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler… | |
| Modificada | Media (4.3) | 2.0% | — | Checkpoint Zonealarm | 21/8/2009 | 16/6/2026 | TrueVector in Check Point ZoneAlarm 8.0.020.000, with vsmon.exe running, allows remote HTTP proxies to cause a denial of service (crash) and disable the HIDS module via a crafted response. | |
| Modificada | Media (6.9) | 1.1% | — | Checkpoint Zonealarm | 19/8/2009 | 16/6/2026 | Buffer overflow in multiscan.exe in Check Point ZoneAlarm Security Suite 7.0.483.000 and 8.0.020.000 allows local users to execute arbitrary code via a file or directory with a long path. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.9) | 0.29% | — | Zonelabs Zonealarm | 24/9/2007 | 16/6/2026 | ZoneAlarm Pro 7.0.362.000 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via the (1) NtCreatePort and (2) NtDeleteFile kernel SSDT hooks, a partial regression of… | |
| Modificada | Alta (7.2) | 0.37% | — | Checkpoint Zonealarm | 21/8/2007 | 16/6/2026 | vsdatant.sys 6.5.737.0 in Check Point Zone Labs ZoneAlarm before 7.0.362 allows local users to gain privileges via a crafted Interrupt Request Packet (Irp) in a METHOD_NEITHER (1) IOCTL 0x8400000F or (2) IOCTL 0x84000013 request, which can be used to overwrite arbitrary memory locations. | |
| Modificada | Alta (7.2) | 0.32% | — | Checkpoint ZonealarmComodo Firewall PROComodo Personal Firewall | 16/5/2007 | 16/6/2026 | Check Point ZoneAlarm Pro before 6.5.737.000 does not properly test for equivalence of process identifiers for certain Microsoft Windows API functions in the NT kernel 5.0 and greater, which allows local users to call these functions, and bypass firewall rules or gain privileges, via a modified identifier that is one,… | |
| Modificada | Media (4.9) | 0.34% | — | Zonelabs Zonealarm | 2/5/2007 | 16/6/2026 | ZoneAlarm Pro 6.5.737.000, 6.1.744.001, and possibly earlier versions and other products, allows local users to cause a denial of service (system crash) by sending malformed data to the vsdatant device driver, which causes an invalid memory access. | |
| Modificada | Alta (7.2) | 0.41% | — | Checkpoint Zonealarm | 24/4/2007 | 16/6/2026 | The IOCTL handling in srescan.sys in the ZoneAlarm Spyware Removal Engine (SRE) in Check Point ZoneAlarm before 5.0.156.0 allows local users to execute arbitrary code via certain IOCTL lrp parameter addresses. | |
| Modificada | Media (6.9) | 0.77% | — | Zonelabs Zonealarm | 18/4/2007 | 16/6/2026 | vsdatant.sys in Check Point Zone Labs ZoneAlarm Pro before 7.0.302.000 does not validate certain arguments before being passed to hooked SSDT function handlers, which allows local users to cause a denial of service (system crash) or possibly execute arbitrary code via crafted arguments to the (1) NtCreateKey and (2)… | |
| Modificada | Media (6.2) | 0.29% | — | Zonelabs Zonealarm | 19/1/2007 | 16/6/2026 | Microsoft Windows XP and Windows Server 2003 do not properly handle user logoff, which might allow local users to gain the privileges of a previous system user, possibly related to user profile unload failure. NOTE: it is not clear whether this is an issue in Windows itself, or an interaction with another product. The… | |
| Modificada | Media (4.9) | 0.63% | — | Zonelabs Zonealarm Security Suite | 13/7/2006 | 16/6/2026 | Check Point Zone Labs ZoneAlarm Internet Security Suite 6.5.722.000, 6.1.737.000, and possibly other versions do not properly validate RegSaveKey, RegRestoreKey, and RegDeleteKey function calls, which allows local users to cause a denial of service (system crash) via a certain combination of these function calls with… | |
| Modificada | Media (6.2) | 0.52% | — | Zonelabs Zonealarm Security Suite | 14/3/2006 | 16/6/2026 | Untrusted search path vulnerability in the TrueVector service (VSMON.exe) in Zone Labs ZoneAlarm 6.x and Integrity does not search ZoneAlarm's own folders before other folders that are specified in a user's PATH, which might allow local users to execute code as SYSTEM by placing malicious DLLs into a folder that has… | |
| Modificada | Alta (7.2) | 0.35% | — | Checkpoint ZonealarmCheckpoint Zonealarm Security Suite | 31/12/2005 | 16/6/2026 | Multiple Check Point Zone Labs ZoneAlarm products before 7.0.362, including ZoneAlarm Security Suite 5.5.062.004 and 6.5.737, use insecure default permissions for critical files, which allows local users to gain privileges or bypass security controls. |