CVE-2021-30359
The Harmony Browse and the SandBlast Agent for Browsers installers must have admin privileges to execute some steps during the installation. Because the MS Installer allows regular users to repair their installation, an attacker running an installer before 90.08.7405 can start the installation repair and place a specially crafted binary in the repair folder, which runs with the admin privileges.
Published:Oct 22, 2021
Last Modified:Nov 21, 2024
EPS:Oct 22, 2021
EPSS Score:0.00061
CVSS Score:7.8
Affected Products
Vendor
Product
Action
Vendor
Checkpoint
Product
Harmony Browse
Checkpoint
Harmony Browse
Vendor
Checkpoint
Product
Sandblast Agent For Browsers
Checkpoint
Sandblast Agent For Browsers
Vendor
Microsoft
Product
Windows
Microsoft
Windows
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
