Privilege Escalation in Check Point Harmony Browse and SandBlast Agent for Browsers Installers
CVE-2021-30359
Key Information:
- Vendor
Checkpoint
- Vendor
- CVE Published:
- 22 October 2021
What is CVE-2021-30359?
A security issue exists in Check Point's Harmony Browse and SandBlast Agent for Browsers due to improper privilege handling during the installation process. The installers require administrative privileges for certain steps, yet the Microsoft Installer allows standard users to perform repairs on installations. This misconfiguration permits an attacker to exploit the installation process by triggering a repair operation using a malicious installer version prior to 90.08.7405, enabling the insertion of a specially crafted binary into the repair folder. When executed, this binary operates with elevated admin privileges, potentially compromising system integrity and security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Check Point Harmony Browse and SandBlast Agent for Browsers before 90.08.7405
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved