CVE-2019-8461
Check Point Endpoint Security Initial Client for Windows before version E81.30 tries to load a DLL placed in any PATH location on a clean image without Endpoint Client installed. An attacker can leverage this to gain LPE using a specially crafted DLL placed in any PATH location accessible with write permissions to the user.
Published:Aug 29, 2019
Last Modified:Nov 21, 2024
EPS:Aug 29, 2019
EPSS Score:0.00164
CVSS Score:7.8
Affected Products
Vendor
Product
Action
Vendor
Checkpoint
Product
Capsule Docs Standalone Client
Checkpoint
Capsule Docs Standalone Client
Vendor
Checkpoint
Product
Endpoint Security
Checkpoint
Endpoint Security
Vendor
Checkpoint
Product
Remote Access Clients
Checkpoint
Remote Access Clients
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
