PT-2020-18889 · Check Point Software Technologies · Check Point Endpoint Security Client For Windows

Published

2020-10-30

·

Updated

2020-11-19

·

CVE-2020-6014

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Check Point Endpoint Security Client for Windows versions prior to E83.20
Description The issue arises when the Check Point Endpoint Security Client for Windows, with Anti-Bot or Threat Emulation blades installed, attempts to load a non-existent DLL during a Domain Name query. An attacker with administrator privileges can exploit this to achieve code execution within a Check Point Software Technologies signed binary. Under certain circumstances, this may cause the client to terminate.
Recommendations For versions prior to E83.20, update to version E83.20 or later to resolve the issue. As a temporary workaround, consider restricting administrator privileges to minimize the risk of exploitation.

Fix

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-6014

Affected Products

Check Point Endpoint Security Client For Windows