PT-2012-4239 · Check Point · Check Point Remote Access Client+2
Published
2012-06-19
·
Updated
2012-06-26
·
CVE-2012-2753
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Check Point Endpoint Security versions R73.x through R80.x
Check Point Endpoint Connect versions R73.x
Check Point Endpoint Security VPN version R75
Check Point Remote Access Clients versions E75.x
Description
The issue is related to an untrusted search path vulnerability in TrGUI.exe, part of the Endpoint Connect GUI in Check Point Endpoint Security. This vulnerability allows local users to gain privileges by using a Trojan horse DLL in the current working directory.
Recommendations
For Check Point Endpoint Security versions R73.x through R80.x, update to a version that includes a fix for this issue.
For Check Point Endpoint Connect versions R73.x, update to a version that includes a fix for this issue.
For Check Point Endpoint Security VPN version R75, update to a version that includes a fix for this issue.
For Check Point Remote Access Clients versions E75.x, update to a version that includes a fix for this issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Check Point Endpoint Connect
Check Point Endpoint Security
Check Point Remote Access Client