PT-2019-2544 · Check Point · Check Point Endpoint Security Client

Published

2019-04-16

·

Updated

2020-10-22

·

CVE-2019-8454

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Check Point Endpoint Security client for Windows versions prior to E80.96
Description The issue is related to insufficient access control in the Check Point Endpoint Security client, which can be exploited by a local attacker. This can be done by creating a hard-link between a file used by the client and a BAT file, allowing the attacker to write BAT commands that will later be executed by the user or the system. This could impact the confidentiality, integrity, and availability of protected information.
Recommendations For versions prior to E80.96, update to version E80.96 or later to resolve the issue. As a temporary workaround, consider restricting access to the files used by the Check Point Endpoint Security client to minimize the risk of exploitation.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-02392
CVE-2019-8454

Affected Products

Check Point Endpoint Security Client