PT-2012-4239 · Check Point · Check Point Remote Access Client+2

Publicado

2012-06-19

·

Atualizado

2012-06-26

·

CVE-2012-2753

CVSS v2.0

6.9

Média

VetorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Check Point Endpoint Security versions R73.x through R80.x Check Point Endpoint Connect versions R73.x Check Point Endpoint Security VPN version R75 Check Point Remote Access Clients versions E75.x
Description The issue is related to an untrusted search path vulnerability in TrGUI.exe, part of the Endpoint Connect GUI in Check Point Endpoint Security. This vulnerability allows local users to gain privileges by using a Trojan horse DLL in the current working directory.
Recommendations For Check Point Endpoint Security versions R73.x through R80.x, update to a version that includes a fix for this issue. For Check Point Endpoint Connect versions R73.x, update to a version that includes a fix for this issue. For Check Point Endpoint Security VPN version R75, update to a version that includes a fix for this issue. For Check Point Remote Access Clients versions E75.x, update to a version that includes a fix for this issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2012-2753

Produtos afetados

Check Point Endpoint Connect
Check Point Endpoint Security
Check Point Remote Access Client