Checkpoint Remote Access Clients vulnerabilities

4 known vulnerabilities affecting checkpoint/remote_access_clients.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2019-8461HIGHCVSS 7.8fixed in e81.302019-08-29
CVE-2019-8461 [HIGH] CWE-114 CVE-2019-8461: Check Point Endpoint Security Initial Client for Windows before version E81.30 tries to load a DLL p Check Point Endpoint Security Initial Client for Windows before version E81.30 tries to load a DLL placed in any PATH location on a clean image without Endpoint Client installed. An attacker can leverage this to gain LPE using a specially crafted DLL placed in any PATH location accessible with write permissions to the user.
nvd
CVE-2019-8459CRITICALCVSS 9.8fixed in e80.832019-06-20
CVE-2019-8459 [CRITICAL] CWE-428 CVE-2019-8459: Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the path. This can cause loading of a previously placed executable with a name similar to the parts of the path, instead of the intended one.
nvd
CVE-2019-8458MEDIUMCVSS 4.4fixed in e81.002019-06-20
CVE-2019-8458 [MEDIUM] CWE-114 CVE-2019-8458: Check Point Endpoint Security Client for Windows, with Anti-Malware blade installed, before version Check Point Endpoint Security Client for Windows, with Anti-Malware blade installed, before version E81.00, tries to load a non-existent DLL during an update initiated by the UI. An attacker with administrator privileges can leverage this to gain code execution within a Check Point Software Technologies signed binary, where under certain circumstances
nvd
CVE-2012-2753MEDIUMCVSS 6.9ve75ve75.10+1 more2012-06-19
CVE-2012-2753 [MEDIUM] CVE-2012-2753: Untrusted search path vulnerability in TrGUI.exe in the Endpoint Connect (aka EPC) GUI in Check Poin Untrusted search path vulnerability in TrGUI.exe in the Endpoint Connect (aka EPC) GUI in Check Point Endpoint Security R73.x and E80.x on the VPN blade platform, Endpoint Security VPN R75, Endpoint Connect R73.x, and Remote Access Clients E75.x allows local users to gain privileges via a Trojan horse DLL in the current working directory.
nvd