Unquoted Windows Search Path Vulnerability in Check Point VPN-1 SecureClient
CVE-2006-0255

Currently unrated

Key Information:

Vendor

Checkpoint

Status
Vendor
CVE Published:
18 January 2006

What is CVE-2006-0255?

A security flaw in Check Point VPN-1 SecureClient arises from an unquoted Windows search path which may permit local users to escalate privileges. When the SecureClient application attempts to launch the Sr_GUI.exe program, it inadvertently relies on potentially malicious executables, such as a crafted 'program.exe' placed in the C: directory. This setup can lead to unauthorized access and exploitation of the system, allowing local users to take undue control over the application.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.