PT-2019-19052 · Check Point Software Technologies · Check Point Endpoint Security Client
Published
2019-06-20
·
Updated
2020-10-22
·
CVE-2019-8458
CVSS v3.1
4.4
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Check Point Endpoint Security Client for Windows versions prior to E81.00
Description
The issue occurs when the Check Point Endpoint Security Client for Windows, with the Anti-Malware blade installed, attempts to load a non-existent DLL during an update initiated by the UI. An attacker with administrator privileges can exploit this to gain code execution within a Check Point Software Technologies signed binary. Under certain circumstances, this may cause the client to terminate.
Recommendations
For versions prior to E81.00, update to version E81.00 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Check Point Endpoint Security Client