ZoneAlarm Firewall Can Be Bypassed
ZoneAlarm firewall can be bypassed by using interprocess communication (IPC) and direct data exchange (DDE).
September 29, 2005
ReportedSeptember 28, 2005 by Debasis Mohanty
VERSIONSAFFECTED
ZoneAlarmFirewall, free versions |
DESCRIPTION
ZoneLabs' ZoneAlarm firewall can be bypassed by using Dynamic DataExchange (DDE) and interprocess communications (IPC). A maliciousprogram could gain access beyond the firewall through IPC-DDE and atrusted program that's allowed access through the firewall.
VENDORRESPONSE
ZoneLabs reports that only free versions of ZoneAlarm firewall areaffected because they lack Advanced Program Control, which is foundin ZoneAlarm Pro, ZoneAlarm AntiVirus, ZoneAlarm Wireless Security,and ZoneAlarm Security Suite. Users of products with Advanced Program Control should ensure that it is enabled in order to defendagainst these types of attacks. All ZoneAlarm users, including users ofthe free version, should also ensure that they have the latestversion of the products installed.
About the Author
You May Also Like