MEDIUM🇵🇱 Wersja polska

CVE-2019-8458

CVSS 4.4v3.1pub. 2019-06-20upd. 2024-11-21

Check Point Endpoint Security Client for Windows, with Anti-Malware blade installed, before version E81.00, tries to load a non-existent DLL during an update initiated by the UI. An attacker with administrator privileges can leverage this to gain code execution within a Check Point Software Technologies signed binary, where under certain circumstances may cause the client to terminate.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H
  • Checkpoint Capsule Docs

    APP
    Checkpoint
    < e81.00
  • Checkpoint Endpoint Security Clients

    APP
    Checkpoint
    < e81.00
  • Checkpoint Remote Access Clients

    APP
    Checkpoint
    < e81.00
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2019-8459CRITICAL9.8PL ✓same product

Check Point Endpoint Security Client – privilege escalation przez niecytowaną ścieżkę (Unquoted Service Path)

CVE-2019-8463HIGH7.5same product

A denial of service vulnerability was reported in Check Point Endpoint Security Client for Windows before E82....

CVE-2019-8461HIGH7.8same product

Check Point Endpoint Security Initial Client for Windows before version E81.30 tries to load a DLL placed in a...

CVE-2012-2753MEDIUM6.9same product

Untrusted search path vulnerability in TrGUI.exe in the Endpoint Connect (aka EPC) GUI in Check Point Endpoint...

CVE-2026-16232CRITICAL9.3⚠ KEVPL ✓same vendor

Authentication bypass w Check Point SmartConsole — pełny dostęp administratora