Check Point Endpoint Security Initial Client for Windows before version E81.30 tries to load a DLL placed in any PATH location on a clean image without Endpoint Client installed. An attacker can leverage this to gain LPE using a specially crafted DLL placed in any PATH location accessible with write permissions to the user.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-17851 Check Point Endpoint Security Initial Client for Windows before version E81.30 tries to load a DLL placed in any PATH location on a clean image without Endpoint Client installed. An attacker can leverage this to gain LPE using a specially crafted DLL placed in any PATH location accessible with write permissions to the user.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: checkpoint

Published:

Updated: 2024-08-04T21:17:31.435Z

Reserved: 2019-02-18T00:00:00

Link: CVE-2019-8461

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-08-29T21:15:11.400

Modified: 2024-11-21T04:49:56.977

Link: CVE-2019-8461

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.