Check Point ZoneAlarm Extreme Security Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Check Point ZoneAlarm Extreme Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

The specific flaw exists within the Forensic Recorder service. By creating a symbolic link, an attacker can abuse the service to overwrite arbitrary files. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-21677.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-47978 Check Point ZoneAlarm Extreme Security Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Check Point ZoneAlarm Extreme Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Forensic Recorder service. By creating a symbolic link, an attacker can abuse the service to overwrite arbitrary files. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-21677.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 16 Jan 2026 02:00:00 +0900

Type Values Removed Values Added
First Time appeared Checkpoint zonealarm Extreme Security Nextgen
CPEs cpe:2.3:a:checkpoint:zonealarm_extreme_security:4.0.148.0:*:*:*:*:*:*:* cpe:2.3:a:checkpoint:zonealarm_extreme_security_nextgen:4.0.148:*:*:*:*:*:*:*
Vendors & Products Checkpoint zonealarm Extreme Security
Checkpoint zonealarm Extreme Security Nextgen

Sat, 16 Aug 2025 02:30:00 +0900

Type Values Removed Values Added
First Time appeared Checkpoint
Checkpoint zonealarm Extreme Security
CPEs cpe:2.3:a:checkpoint:zonealarm_extreme_security:4.0.148.0:*:*:*:*:*:*:*
Vendors & Products Checkpoint
Checkpoint zonealarm Extreme Security

Sat, 23 Nov 2024 06:15:00 +0900

Type Values Removed Values Added
First Time appeared Check Point
Check Point zonealarm Extreme Security
CPEs cpe:2.3:a:check_point:zonealarm_extreme_security:4.0.148.0:*:*:*:*:*:*:*
Vendors & Products Check Point
Check Point zonealarm Extreme Security
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 23 Nov 2024 05:15:00 +0900

Type Values Removed Values Added
Description Check Point ZoneAlarm Extreme Security Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Check Point ZoneAlarm Extreme Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Forensic Recorder service. By creating a symbolic link, an attacker can abuse the service to overwrite arbitrary files. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-21677.
Title Check Point ZoneAlarm Extreme Security Link Following Local Privilege Escalation Vulnerability
Weaknesses CWE-59
References
Metrics cvssV3_0

{'score': 7.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published:

Updated: 2024-11-22T20:55:29.976Z

Reserved: 2024-06-20T21:51:41.913Z

Link: CVE-2024-6233

cve-icon Vulnrichment

Updated: 2024-11-22T20:54:56.888Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-22T20:15:11.437

Modified: 2026-01-15T16:48:35.403

Link: CVE-2024-6233

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses