A local attacker can erscalate privileges on affected Check Point ZoneAlarm ExtremeSecurity NextGen, Identity Agent for Windows, and Identity Agent for Windows Terminal Server. To exploit this vulnerability, an attacker must first obtain the ability to execute local privileged code on the target system.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-22273 A local attacker can erscalate privileges on affected Check Point ZoneAlarm ExtremeSecurity NextGen, Identity Agent for Windows, and Identity Agent for Windows Terminal Server. To exploit this vulnerability, an attacker must first obtain the ability to execute local privileged code on the target system.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 16 Jan 2026 02:00:00 +0900

Type Values Removed Values Added
First Time appeared Checkpoint zonealarm Extreme Security Nextgen
CPEs cpe:2.3:a:checkpoint:zonealarm_extreme_security_nextgen:*:*:*:*:*:*:*:*
Vendors & Products Checkpoint zonealarm Extreme Security Nextgen

Mon, 29 Sep 2025 22:00:00 +0900

Type Values Removed Values Added
Description AlocalattackercanescalateprivilegesonaffectedCheckPointZoneAlarmExtremeSecurityNextGen,IdentityAgentforWindows,andIdentityAgentforWindowsTerminalServer.Toexploitthisvulnerability,anattackermustfirstobtaintheabilitytoexecutelocalprivilegedcodeonthetargetsystem. A local attacker can erscalate privileges on affected Check Point ZoneAlarm ExtremeSecurity NextGen, Identity Agent for Windows, and Identity Agent for Windows Terminal Server. To exploit this vulnerability, an attacker must first obtain the ability to execute local privileged code on the target system.

Mon, 29 Sep 2025 20:15:00 +0900

Type Values Removed Values Added
CPEs cpe:2.3:a:checkpoint:identity_agent:-:*:*:*:*:*:*:*
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 29 Sep 2025 19:30:00 +0900

Type Values Removed Values Added
Description A local attacker can escalate privileges on affected Check Point ZoneAlarm Extreme Security NextGen, Identity Agent for Windows, and Identity Agent for Windows Terminal Server. To exploit this vulnerability, an attacker must first obtain the ability to execute local privileged code on the target system. AlocalattackercanescalateprivilegesonaffectedCheckPointZoneAlarmExtremeSecurityNextGen,IdentityAgentforWindows,andIdentityAgentforWindowsTerminalServer.Toexploitthisvulnerability,anattackermustfirstobtaintheabilitytoexecutelocalprivilegedcodeonthetargetsystem.
Title Local privilege escalation in Check Point ZoneAlarm Extreme Security NextGen, Identity Agent for Windows, and Identity Agent for Windows Terminal Server via crafted DLL file LocalprivilegeescalationinCheckPointZoneAlarmExtremeSecurityNextGen,IdentityAgentforWindows,andIdentityAgentforWindowsTerminalServerviacraftedDLLfile

Wed, 27 Aug 2025 03:45:00 +0900

Type Values Removed Values Added
First Time appeared Checkpoint
Checkpoint identity Agent
Checkpoint zonealarm Extreme Security
Microsoft
Microsoft windows
CPEs cpe:2.3:a:checkpoint:identity_agent:*:*:*:*:*:*:*:*
cpe:2.3:a:checkpoint:zonealarm_extreme_security:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Checkpoint
Checkpoint identity Agent
Checkpoint zonealarm Extreme Security
Microsoft
Microsoft windows

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: checkpoint

Published:

Updated: 2025-09-29T12:30:45.141Z

Reserved: 2024-02-01T15:19:26.278Z

Link: CVE-2024-24910

cve-icon Vulnrichment

Updated: 2024-08-01T23:36:20.218Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-18T18:15:09.197

Modified: 2026-01-15T16:48:58.680

Link: CVE-2024-24910

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses