Privilege Escalation Vulnerability in Check Point Endpoint Security Client for Windows
CVE-2019-8461
7.8HIGH
Key Information:
- Vendor
Checkpoint
- Vendor
- CVE Published:
- 29 August 2019
What is CVE-2019-8461?
The Check Point Endpoint Security Initial Client for Windows before version E81.30 is vulnerable to a privilege escalation attack. The issue arises when the client attempts to load a dynamic-link library (DLL) from any designated PATH location on a system where the client is not pre-installed. By placing a specially crafted DLL with write permissions in an accessible PATH location, an attacker can exploit this design flaw to gain elevated privileges and potentially execute arbitrary code with elevated SYSTEM privileges.
Affected Version(s)
Check Point Endpoint Security Initial Client for Windows before version E81.30