CVE-2019-8458

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/06/2019
Last modified:
22/10/2020

Description

Check Point Endpoint Security Client for Windows, with Anti-Malware blade installed, before version E81.00, tries to load a non-existent DLL during an update initiated by the UI. An attacker with administrator privileges can leverage this to gain code execution within a Check Point Software Technologies signed binary, where under certain circumstances may cause the client to terminate.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:checkpoint:endpoint_security_clients:*:*:*:*:*:windows:*:* e81.00 (excluding)
cpe:2.3:a:checkpoint:remote_access_clients:*:*:*:*:*:windows:*:* e81.00 (excluding)
cpe:2.3:a:checkpoint:capsule_docs:*:*:*:*:*:*:*:* e81.00 (excluding)