Local Credential Caching Flaw in Check Point VPN-1 SecuRemote for Windows
CVE-2008-0662
What is CVE-2008-0662?
The Auto Local Logon feature in Check Point's VPN-1 SecuRemote/SecureClient NGX versions R60 and R56 for Windows has a security flaw that allows local users to exploit overly permissive access rights. The vulnerability stems from the fact that credentials are cached under the Checkpoint\SecuRemote registry key, which permits 'Everyone' full control permissions. Consequently, unauthorized local users can read and reuse compromised credentials to gain elevated privileges within the system. Organizations using this software should take immediate action to mitigate potential risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved