Check Point Endpoint Security Client for Windows, with Anti-Malware blade installed, before version E81.00, tries to load a non-existent DLL during an update initiated by the UI. An attacker with administrator privileges can leverage this to gain code execution within a Check Point Software Technologies signed binary, where under certain circumstances may cause the client to terminate.
References
Link | Resource |
---|---|
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk153053 | Vendor Advisory |
Information
Published : 2019-06-20 10:15
Updated : 2020-10-22 10:19
NVD link : CVE-2019-8458
Mitre link : CVE-2019-8458
JSON object : View
CWE
Products Affected
checkpoint
- endpoint_security_clients
- remote_access_clients
- capsule_docs