CVE-2007-2174
highCVSS v3 Base Score
7.2
AV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS Score
0.1%
Exploitation probability in 30 days
Top 79% most likely to be exploited
Attack Characteristics
Attack Vector
Local
Attack Complexity
Low
Confidentiality
C
Integrity
C
Availability
C
Published: April 24, 2007 (6959 days ago)
Last Modified: April 23, 2026
Vendor: Check Point
Source: NVD
Vulnerability Report
Generated by CyberWatcher
Description
The IOCTL handling in srescan.sys in the ZoneAlarm Spyware Removal Engine (SRE) in Check Point ZoneAlarm before 5.0.156.0 allows local users to execute arbitrary code via certain IOCTL lrp parameter addresses.
CWE
NVD-CWE-OtherAffected Products
checkpoint zonealarm