CVE-2020-6014

Severity CVSS v4.0:
Pending analysis
Type:
CWE-426 Untrusted Search Path
Publication date:
02/11/2020
Last modified:
19/11/2020

Description

Check Point Endpoint Security Client for Windows, with Anti-Bot or Threat Emulation blades installed, before version E83.20, tries to load a non-existent DLL during a query for the Domain Name. An attacker with administrator privileges can leverage this to gain code execution within a Check Point Software Technologies signed binary, where under certain circumstances may cause the client to terminate.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:checkpoint:endpoint_security:*:*:*:*:*:windows:*:* e83.20 (excluding)


References to Advisories, Solutions, and Tools