Privilege Escalation in Check Point Harmony Browse and SandBlast Agent for Browsers Installers
CVE-2021-30359
Key Information:
- Vendor
- Checkpoint
- Vendor
- CVE Published:
- 22 October 2021
Summary
A security issue exists in Check Point's Harmony Browse and SandBlast Agent for Browsers due to improper privilege handling during the installation process. The installers require administrative privileges for certain steps, yet the Microsoft Installer allows standard users to perform repairs on installations. This misconfiguration permits an attacker to exploit the installation process by triggering a repair operation using a malicious installer version prior to 90.08.7405, enabling the insertion of a specially crafted binary into the repair folder. When executed, this binary operates with elevated admin privileges, potentially compromising system integrity and security.
Affected Version(s)
Check Point Harmony Browse and SandBlast Agent for Browsers before 90.08.7405
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved