{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"state":"PUBLISHED","cveId":"CVE-2022-23743","assignerOrgId":"897c38be-0345-43cd-b6cf-fe179e0c4f45","assignerShortName":"checkpoint","dateUpdated":"2024-08-03T03:51:45.917Z","dateReserved":"2022-01-19T00:00:00.000Z","datePublished":"2022-05-11T00:00:00.000Z"},"containers":{"cna":{"providerMetadata":{"orgId":"897c38be-0345-43cd-b6cf-fe179e0c4f45","shortName":"checkpoint","dateUpdated":"2022-11-30T00:00:00.000Z"},"descriptions":[{"lang":"en","value":"Check Point ZoneAlarm before version 15.8.200.19118 allows a local actor to escalate privileges during the upgrade process. In addition, weak permissions in the ProgramData\\CheckPoint\\ZoneAlarm\\Data\\Updates directory allow a local attacker the ability to execute an arbitrary file write, leading to execution of code as local system, in ZoneAlarm versions before v15.8.211.192119"}],"affected":[{"vendor":"n/a","product":"ZoneAlarm.","versions":[{"version":"before v15.8.211.192119","status":"affected"}]}],"references":[{"url":"https://www.zonealarm.com/software/extreme-security/release-history"}],"problemTypes":[{"descriptions":[{"type":"CWE","lang":"en","description":"CWE-269: Improper Privilege Management","cweId":"CWE-269"}]}]},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-03T03:51:45.917Z"},"title":"CVE Program Container","references":[{"url":"https://www.zonealarm.com/software/extreme-security/release-history","tags":["x_transferred"]}]}]}}