ZeroHour

CVE-2019-8459

CVSS 3.0
9.8 critical
EPSS
1%p66
Published
()
Modified
Description

Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the path. This can cause loading of a previously placed executable with a name similar to the parts of the path, instead of the intended one.

Vendors
checkpoint
Products
jumbo hotfix for endpoint security server, endpoint security server package, smartconsole for endpoint security server, endpoint security clients, remote access clients, capsule docs standalone client
Weakness
CWE-428
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.