checkpoint zonealarm-anti-ransomware CVE-2020-6012 is a vulnerability in Check Point Software Zonealarm Anti Ransomware
Published on August 4, 2020

ZoneAlarm Anti-Ransomware before version 1.0.713 copies files for the report from a directory with low privileges. A sophisticated timed attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on unpatched systems or using symbolic links. This allows an unprivileged user to enable escalation of privilege via local access.

NVD

Weakness Type

What is an insecure temporary file Vulnerability?

The software attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

CVE-2020-6012 has been classified to as an insecure temporary file vulnerability or weakness.


Products Associated with CVE-2020-6012

Want to know whenever a new CVE is published for Check Point Software Zonealarm Anti Ransomware? stack.watch will email you.

 

Exploit Probability

EPSS
0.19%
Percentile
40.83%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.