>> Zone Labs ZoneAlarm Personal Firewalls Security Bypass Weakness
Title : Zone Labs ZoneAlarm Personal Firewalls Security Bypass Weakness VUPEN ID : VUPEN/ADV-2005-1919 CVE ID : GENERIC-MAP-NOMATCH CWE ID : CWE-
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2005-10-01
Technical Description
A weakness has been identified in Zone Labs ZoneAlarm, which could be exploited to bypass certain security policies. This issue is due to a design error when handling DDE-IPC (Direct Data Exchange – Interprocess Communications), which could be exploited by a malicious program to access the network via a trusted program without warning from the firewall.
Subscribe to VUPEN VNS and receive real-time e-mail and SMS alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback If you have additional information or corrections for this security advisory please submit them via our contact form.