PT-2019-2544 · Check Point · Check Point Endpoint Security Client

Publicado

2019-04-16

·

Atualizado

2020-10-22

·

CVE-2019-8454

CVSS v3.1

7.0

Alta

VetorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Check Point Endpoint Security client for Windows versions prior to E80.96
Description The issue is related to insufficient access control in the Check Point Endpoint Security client, which can be exploited by a local attacker. This can be done by creating a hard-link between a file used by the client and a BAT file, allowing the attacker to write BAT commands that will later be executed by the user or the system. This could impact the confidentiality, integrity, and availability of protected information.
Recommendations For versions prior to E80.96, update to version E80.96 or later to resolve the issue. As a temporary workaround, consider restricting access to the files used by the Check Point Endpoint Security client to minimize the risk of exploitation.

Correção

Link Following

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-02392
CVE-2019-8454

Produtos afetados

Check Point Endpoint Security Client