CVE-2006-3540 describes a denial-of-service vulnerability in Check Point Zone Labs ZoneAlarm Internet Security Suite versions 6.5.722.000, 6.1.737.000, and potentially others. The flaw stems from insufficient validation of specific registry function calls (RegSaveKey, RegRestoreKey, RegDeleteKey) when used with a particular HKEY_LOCAL_MACHINE path. This allows a local attacker to trigger a system crash. The vulnerability has a CVSS score of 4.9, indicating a medium severity. It requires local access (AV:L) and has low attack complexity (AC:L), with the primary impact being a complete system availability loss (A:C). There is no evidence of active exploitation, nor is there publicly available exploit code in Metasploit or ExploitDB. The vulnerability has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.1.737.000CPE matchmatch criteria | cpe:2.3:a:zonelabs:zonealarm_security_suite:6.1.737.000:*:*:*:*:*:*:* | ||
6.5.722.000CPE matchmatch criteria | cpe:2.3:a:zonelabs:zonealarm_security_suite:6.5.722.000:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:N/I:N/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.