> Source: [sk183422](https://support.checkpoint.com/results/sk/sk183422)

# sk183422 - ZoneAlarm Driver Vulnerability Remediation Utility

| Property | Value |
|----------|-------|
| Solution ID | sk183422 |
| Date Created | 2025-05-04 |
| Last Modified | 2025-05-06 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |
| OS | Windows |

## Solution

**About the vulnerability** A vulnerability has been identified in some *vsdatant.sys* driver versions that can potentially be exploited to not allow enabling Windows' "Core Isolation" feature. **Remediation Solution**   
The utility blocks vulnerable *vsdatant* driver versions from loading and uninstalls legacy versions of ZoneAlarm if present. Running the utility blocks future exploits based on vulnerable versions of *vsdatant* driver.  

**Technical Details**   
*CleanZaDrv.exe* installs policies that block loading vulnerable drivers presenting security risks. The utility uninstalls deprecated software installations if present.  

**System Compatibility**   
Windows 10 (all editions and version updates)  
Windows 11 (all editions and version updates)  

**Installation**   

1. Download the utility using this link [ZoneAlarm Driver Cleaner](https://download.zonealarm.com/bin/free/support/download/CleanZaDrv.exe)
2. Double-click the utility to run it.  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk183422/1202505041834501.jpg)  

3. Accept the elevation of privileges request when prompted.
4. The utility applies the blocking policy and uninstall legacy ZoneAlarm software if present.  

5. Restart your computer when prompted after completion.

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk183422/Picture2202505041835272.jpg)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
