CVE-2019-8459

Severity CVSS v4.0:
Pending analysis
Type:
CWE-428 Unquoted Search Path or Element
Publication date:
20/06/2019
Last modified:
09/10/2019

Description

Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the path. This can cause loading of a previously placed executable with a name similar to the parts of the path, instead of the intended one.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:checkpoint:jumbo_hotfix_for_endpoint_security_server:*:*:*:*:*:*:*:* r77.30 (excluding)
cpe:2.3:a:checkpoint:endpoint_security_server_package:*:*:*:*:gaia:*:*:* r77.30.03 (excluding)
cpe:2.3:a:checkpoint:smartconsole_for_endpoint_security_server:*:*:*:*:*:*:*:* r77.30.03 (excluding)
cpe:2.3:a:checkpoint:smartconsole_for_endpoint_security_server:e80.83:*:*:*:*:*:*:*
cpe:2.3:a:checkpoint:endpoint_security_clients:*:*:*:*:*:windows:*:* e80.83 (excluding)
cpe:2.3:a:checkpoint:remote_access_clients:*:*:*:*:*:windows:*:* e80.83 (excluding)
cpe:2.3:a:checkpoint:capsule_docs_standalone_client:*:*:*:*:*:*:*:* e80.82 (excluding)