Search

Find a vulnerability

Search criteria

    19 vulnerabilities by Check Point

    CERTFR-2026-AVI-1219

    Vulnerability from certfr_avis - Published: 2026-09-23 - Updated: 2026-09-23

    Une vulnérabilité a été découverte dans Check Point Security Management Server. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance et une atteinte à l'intégrité des données.

    L'éditeur indique que la vulnérabilité CVE-2026-93616 est activement exploitée.

    Check Point propose de limiter l'accès à l'interface d'administration et de ne pas l'exposer sur Internet. Des indicateurs de compromission sont disponibles dans l'avis de l'éditeur.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    Check Point Multi-Domain Security Management Multi-Domain Security Management Server sans le correctif R82.20
    Check Point Security Management Security Management Server sans le correctif R82.20
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Multi-Domain Security Management Server sans le correctif R82.20",
          "product": {
            "name": "Multi-Domain Security Management",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Security Management Server sans le correctif R82.20",
          "product": {
            "name": "Security Management",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-93616",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-93616"
        }
      ],
      "initial_release_date": "2026-09-23T00:00:00",
      "last_revision_date": "2026-09-23T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-1219",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-09-23T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        },
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans Check Point Security Management Server. Elle permet \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance et une atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es.\n\nL\u0027\u00e9diteur indique que la vuln\u00e9rabilit\u00e9 CVE-2026-93616 est activement exploit\u00e9e.\n\nCheck Point propose de limiter l\u0027acc\u00e8s \u00e0 l\u0027interface d\u0027administration et de ne pas l\u0027exposer sur Internet. Des indicateurs de compromission sont disponibles dans l\u0027avis de l\u0027\u00e9diteur.",
      "title": "Vuln\u00e9rabilit\u00e9 dans Check Point Security Management Server",
      "vendor_advisories": [
        {
          "published_at": "2026-09-22",
          "title": "Bulletin de s\u00e9curit\u00e9 Check Point sk1000171",
          "url": "https://support.checkpoint.com/results/sk/sk1000171"
        }
      ]
    }

    CERTFR-2026-AVI-1193

    Vulnerability from certfr_avis - Published: 2026-09-17 - Updated: 2026-09-17

    Une vulnérabilité a été découverte dans les produits Check Point. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance.

    Indicateurs de compromission

    Checkpoint recommande de rechercher, via la SmartConsole, le motif "Administrator failed to log in: Username too long" dans les journaux Audit et Admin login.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    Check Point Security Management Security Management Server versions antérieures à R81.20 take 28
    Check Point Security Management Security Management Server versions R82 antérieures à R82 take 28
    Check Point Multi-Domain Log Server Multi-Domain Log Server versions R82.20 antérieures à R82.20 take29
    Check Point Security Management Security Management Server versions R82.20 antérieures à R82.20 take29
    Check Point Multi-Domain Log Server Multi-Domain Log Server versions R82.10 antérieures à R82.10 take 28
    Check Point Multi-Domain Security Management Multi-Domain Security Management Server versions R82.10 antérieures à R82.10 take 28
    Check Point Security Management Security Management Server versions R82.10 antérieures à R82.10 take 28
    Check Point Multi-Domain Security Management Multi-Domain Security Management Server versions R82 antérieures à R82 take 28
    Check Point Log Server Log Server versions R82.10 antérieures à R82.10 take 28
    Check Point Multi-Domain Log Server Multi-Domain Log Server versions R82 antérieures à R82 take 28
    Check Point Log Server Log Server versions R82.20 antérieures à R82.20 take29
    Check Point Log Server Log Server versions R82 antérieures à R82 take 28
    Check Point Multi-Domain Security Management Multi-Domain Security Management Server versions R82.20 antérieures à R82.20 take29
    Check Point Multi-Domain Log Server Multi-Domain Log Server versions antérieures à R81.20 take 28
    Check Point Multi-Domain Security Management Multi-Domain Security Management Server versions antérieures à R81.20 take 28
    Check Point Log Server Log Server versions antérieures à R81.20 take 28
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Security Management Server versions ant\u00e9rieures \u00e0 R81.20 take 28",
          "product": {
            "name": "Security Management",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Security Management Server versions R82 ant\u00e9rieures \u00e0 R82 take 28",
          "product": {
            "name": "Security Management",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Multi-Domain Log Server versions R82.20 ant\u00e9rieures \u00e0 R82.20 take29",
          "product": {
            "name": "Multi-Domain Log Server",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Security Management Server versions R82.20 ant\u00e9rieures \u00e0 R82.20 take29",
          "product": {
            "name": "Security Management",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Multi-Domain Log Server versions R82.10 ant\u00e9rieures \u00e0 R82.10 take 28",
          "product": {
            "name": "Multi-Domain Log Server",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Multi-Domain Security Management Server versions R82.10 ant\u00e9rieures \u00e0 R82.10 take 28",
          "product": {
            "name": "Multi-Domain Security Management",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Security Management Server versions R82.10 ant\u00e9rieures \u00e0 R82.10 take 28",
          "product": {
            "name": "Security Management",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Multi-Domain Security Management Server versions R82 ant\u00e9rieures \u00e0 R82 take 28",
          "product": {
            "name": "Multi-Domain Security Management",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Log Server versions R82.10 ant\u00e9rieures \u00e0 R82.10 take 28",
          "product": {
            "name": "Log Server",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Multi-Domain Log Server versions R82 ant\u00e9rieures \u00e0 R82 take 28",
          "product": {
            "name": "Multi-Domain Log Server",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Log Server versions R82.20 ant\u00e9rieures \u00e0 R82.20 take29",
          "product": {
            "name": "Log Server",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Log Server versions R82 ant\u00e9rieures \u00e0 R82 take 28",
          "product": {
            "name": "Log Server",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Multi-Domain Security Management Server versions R82.20 ant\u00e9rieures \u00e0 R82.20 take29",
          "product": {
            "name": "Multi-Domain Security Management",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Multi-Domain Log Server versions ant\u00e9rieures \u00e0 R81.20 take 28",
          "product": {
            "name": "Multi-Domain Log Server",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Multi-Domain Security Management Server versions ant\u00e9rieures \u00e0 R81.20 take 28",
          "product": {
            "name": "Multi-Domain Security Management",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Log Server versions ant\u00e9rieures \u00e0 R81.20 take 28",
          "product": {
            "name": "Log Server",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-91843",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-91843"
        }
      ],
      "initial_release_date": "2026-09-17T00:00:00",
      "last_revision_date": "2026-09-17T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-1193",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-09-17T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans les produits Check Point. Elle permet \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance.\n\n## Indicateurs de compromission\n\nCheckpoint recommande de rechercher, via la *SmartConsole*, le motif **\"Administrator failed to log in: Username too long\"** dans les journaux *Audit* et *Admin login*.",
      "title": "Vuln\u00e9rabilit\u00e9 dans les produits Check Point",
      "vendor_advisories": [
        {
          "published_at": "2026-09-16",
          "title": "Bulletin de s\u00e9curit\u00e9 Check Point sk1000155",
          "url": "https://support.checkpoint.com/results/sk/sk1000155"
        }
      ]
    }

    CERTFR-2026-AVI-1152

    Vulnerability from certfr_avis - Published: 2026-09-10 - Updated: 2026-09-10

    De multiples vulnérabilités ont été découvertes dans les produits Check Point. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et un contournement de la politique de sécurité.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    L'éditeur précise que les versions R80, R80.10, R80.20, R80.30, R80.40, R81 et R81.10 de Security Gateways, Security Management Server et des pare-feux Spark sont en fin de service et ne recevront donc pas de correctif.

    Impacted products
    Vendor Product Description
    Check Point Security Management Security Management versions R82 antérieures à R82 take 24
    Check Point Security Management Security Management versions R82.10 antérieures à R82.10 take 24
    Check Point Spark Firewalls Spark Firewalls versions R82.10 antérieures à R82.10 take 24
    Check Point Security Gateway Security Gateway versions R81.20 antérieures à R81.20 take 24
    Check Point Security Gateway Security Gateway versions R82.10 antérieures à R82.10 take 24
    Check Point Spark Firewalls Spark Firewalls versions R81.20 antérieures à R81.20 take 24
    Check Point Spark Firewalls Spark Firewalls versions R82 antérieures à R82 take 24
    Check Point Security Gateway Security Gateway versions R82 antérieures à R82 take 24
    Check Point Security Management Security Management versions R81.20 antérieures à R81.20 take 24
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Security Management versions R82 ant\u00e9rieures \u00e0 R82 take 24",
          "product": {
            "name": "Security Management",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Security Management versions R82.10 ant\u00e9rieures \u00e0 R82.10 take 24",
          "product": {
            "name": "Security Management",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Spark Firewalls versions R82.10 ant\u00e9rieures \u00e0 R82.10 take 24",
          "product": {
            "name": "Spark Firewalls",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Security Gateway versions R81.20 ant\u00e9rieures \u00e0 R81.20 take 24",
          "product": {
            "name": "Security Gateway",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Security Gateway versions R82.10 ant\u00e9rieures \u00e0 R82.10 take 24",
          "product": {
            "name": "Security Gateway",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Spark Firewalls versions R81.20 ant\u00e9rieures \u00e0 R81.20 take 24",
          "product": {
            "name": "Spark Firewalls",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Spark Firewalls versions R82 ant\u00e9rieures \u00e0 R82 take 24",
          "product": {
            "name": "Spark Firewalls",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Security Gateway versions R82 ant\u00e9rieures \u00e0 R82 take 24",
          "product": {
            "name": "Security Gateway",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Security Management versions R81.20 ant\u00e9rieures \u00e0 R81.20 take 24",
          "product": {
            "name": "Security Management",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "L\u0027\u00e9diteur pr\u00e9cise que les versions R80, R80.10, R80.20, R80.30, R80.40, R81 et R81.10 de Security Gateways, Security Management Server et des pare-feux Spark sont en fin de service et ne recevront donc pas de correctif.",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-85102",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-85102"
        },
        {
          "name": "CVE-2026-85103",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-85103"
        }
      ],
      "initial_release_date": "2026-09-10T00:00:00",
      "last_revision_date": "2026-09-10T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-1152",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-09-10T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits Check Point. Elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance et un contournement de la politique de s\u00e9curit\u00e9.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits Check Point",
      "vendor_advisories": [
        {
          "published_at": "2026-09-08",
          "title": "Bulletin de s\u00e9curit\u00e9 Check Point sk1000118",
          "url": "https://support.checkpoint.com/results/sk/sk1000118"
        },
        {
          "published_at": "2026-09-08",
          "title": "Bulletin de s\u00e9curit\u00e9 Check Point sk1000117",
          "url": "https://support.checkpoint.com/results/sk/sk1000117"
        }
      ]
    }

    CERTFR-2026-AVI-0965

    Vulnerability from certfr_avis - Published: 2026-08-04 - Updated: 2026-08-04

    Une vulnérabilité a été découverte dans les produits Check Point. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance et un contournement de la politique de sécurité.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Check Point indique que les versions obsolètes R80, R80.10, R80.20, R80.30, R80.40, R81 et R81.10 sont également affectées.

    Impacted products
    Vendor Product Description
    Check Point Security Management Security Management versions R82.10 antérieures à R82.10 Take 40
    Check Point Security Management Security Management versions R82 antérieures à R82 Take 122
    Check Point Multi-Domain Security Management Multi-Domain Security Management versions R82 antérieures à R82 Take 122
    Check Point Multi-Domain Security Management Multi-Domain Security Management versions R81.20 antérieures à R81.20 Take 161
    Check Point Security Management Security Management versions R81.20 antérieures à R81.20 Take 161
    Check Point Multi-Domain Security Management Multi-Domain Security Management versions R82.10 antérieures à R82.10 Take 40
    References
    Bulletin de sécurité Check Point sk185222 2026-08-02 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Security Management versions R82.10 ant\u00e9rieures \u00e0 R82.10 Take 40",
          "product": {
            "name": "Security Management",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Security Management versions R82 ant\u00e9rieures \u00e0 R82 Take 122",
          "product": {
            "name": "Security Management",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Multi-Domain Security Management versions R82 ant\u00e9rieures \u00e0 R82 Take 122",
          "product": {
            "name": "Multi-Domain Security Management",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Multi-Domain Security Management versions R81.20 ant\u00e9rieures \u00e0 R81.20 Take 161",
          "product": {
            "name": "Multi-Domain Security Management",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Security Management versions R81.20 ant\u00e9rieures \u00e0 R81.20 Take 161",
          "product": {
            "name": "Security Management",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Multi-Domain Security Management versions R82.10 ant\u00e9rieures \u00e0 R82.10 Take 40",
          "product": {
            "name": "Multi-Domain Security Management",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "Check Point indique que les versions obsol\u00e8tes R80, R80.10, R80.20, R80.30, R80.40, R81 et R81.10 sont \u00e9galement affect\u00e9es.",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-18574",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18574"
        }
      ],
      "initial_release_date": "2026-08-04T00:00:00",
      "last_revision_date": "2026-08-04T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-0965",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-08-04T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans les produits Check Point. Elle permet \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance et un contournement de la politique de s\u00e9curit\u00e9.",
      "title": "Vuln\u00e9rabilit\u00e9 dans les produits Check Point",
      "vendor_advisories": [
        {
          "published_at": "2026-08-02",
          "title": "Bulletin de s\u00e9curit\u00e9 Check Point sk185222",
          "url": "https://support.checkpoint.com/results/sk/sk185222"
        }
      ]
    }

    CERTFR-2026-AVI-0912

    Vulnerability from certfr_avis - Published: 2026-07-23 - Updated: 2026-07-23

    De multiples vulnérabilités ont été découvertes dans les produits Check Point. Elles permettent à un attaquant de provoquer une élévation de privilèges et un contournement de la politique de sécurité.

    Check Point indique que la vulnérabilité CVE-2026-16232 est activement exploitée.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    Check Point Security Gateways Security Gateways version R82 sans le dernier correctif de sécurité
    Check Point Security Management Security Management versions antérieures à R81.20 sans le dernier correctif de sécurité
    Check Point Multi-Domain Security Management Multi-Domain Security Management version R82 sans le dernier correctif de sécurité
    Check Point Security Management Security Management version R82.10 sans le dernier correctif de sécurité
    Check Point Multi-Domain Security Management Multi-Domain Security Management version R82.10 sans le dernier correctif de sécurité
    Check Point Security Management Security Management version R82 sans le dernier correctif de sécurité
    Check Point Security Gateways Security Gateways versions antérieures à R81.20 sans le dernier correctif de sécurité
    Check Point Security Gateways Security Gateways version R82.10 sans le dernier correctif de sécurité
    Check Point Multi-Domain Security Management Multi-Domain Security Management versions antérieures à R81.20 sans le dernier correctif de sécurité
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Security Gateways version R82 sans le dernier correctif de s\u00e9curit\u00e9",
          "product": {
            "name": "Security Gateways",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Security Management versions ant\u00e9rieures \u00e0 R81.20 sans le dernier correctif de s\u00e9curit\u00e9",
          "product": {
            "name": "Security Management",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Multi-Domain Security Management version R82 sans le dernier correctif de s\u00e9curit\u00e9",
          "product": {
            "name": "Multi-Domain Security Management",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Security Management version R82.10 sans le dernier correctif de s\u00e9curit\u00e9",
          "product": {
            "name": "Security Management",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Multi-Domain Security Management version R82.10 sans le dernier correctif de s\u00e9curit\u00e9",
          "product": {
            "name": "Multi-Domain Security Management",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Security Management version R82 sans le dernier correctif de s\u00e9curit\u00e9",
          "product": {
            "name": "Security Management",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Security Gateways versions ant\u00e9rieures \u00e0 R81.20 sans le dernier correctif de s\u00e9curit\u00e9",
          "product": {
            "name": "Security Gateways",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Security Gateways version R82.10 sans le dernier correctif de s\u00e9curit\u00e9",
          "product": {
            "name": "Security Gateways",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Multi-Domain Security Management versions ant\u00e9rieures \u00e0 R81.20 sans le dernier correctif de s\u00e9curit\u00e9",
          "product": {
            "name": "Multi-Domain Security Management",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-62144",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-62144"
        },
        {
          "name": "CVE-2026-16232",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-16232"
        },
        {
          "name": "CVE-2026-62145",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-62145"
        }
      ],
      "initial_release_date": "2026-07-23T00:00:00",
      "last_revision_date": "2026-07-23T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-0912",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-07-23T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        },
        {
          "description": "\u00c9l\u00e9vation de privil\u00e8ges"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits Check Point. Elles permettent \u00e0 un attaquant de provoquer une \u00e9l\u00e9vation de privil\u00e8ges et un contournement de la politique de s\u00e9curit\u00e9.\n\nCheck Point indique que la vuln\u00e9rabilit\u00e9 CVE-2026-16232 est activement exploit\u00e9e.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits Check Point",
      "vendor_advisories": [
        {
          "published_at": "2026-07-22",
          "title": "Bulletin de s\u00e9curit\u00e9 Check Point sk185153",
          "url": "https://support.checkpoint.com/results/sk/sk185153"
        },
        {
          "published_at": "2026-07-22",
          "title": "Bulletin de s\u00e9curit\u00e9 Check Point sk185169",
          "url": "https://support.checkpoint.com/results/sk/sk185169"
        },
        {
          "published_at": "2026-07-22",
          "title": "Bulletin de s\u00e9curit\u00e9 Check Point sk185152",
          "url": "https://support.checkpoint.com/results/sk/sk185152"
        }
      ]
    }

    CERTFR-2026-AVI-0711

    Vulnerability from certfr_avis - Published: 2026-06-09 - Updated: 2026-06-09

    De multiples vulnérabilités ont été découvertes dans les VPN Check Point. Elles permettent à un attaquant de provoquer un contournement de la politique de sécurité.

    Check Point indique que la vulnérabilité CVE-2026-50751 est activement exploitée.

    La vulnérabilité CVE-2026-50751 affecte les instances avec le protocole IKEv1 activé.

    L'éditeur fournit également des mesures de contournement ainsi que des indicateurs de compromission. Ceux-ci n'ont pas été qualifiés par le CERT-FR.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    L'éditeur précise que les versions R80.40, R81 et R81.10 de Security Gateways ainsi que les versions R80.20.X des pare-feux Spark sont en fin de vie et ne recevront donc pas de correctif.

    Impacted products
    Vendor Product Description
    Check Point Security Gateways Security Gateways version R81
    Check Point Security Gateways Security Gateways version R81.10
    Check Point Security Gateways Security Gateways version R80.40
    Check Point Security Gateways Security Gateways versions R82.10 et antérieures sans les derniers correctifs de sécurité, se référer aux bulletins de sécurité de l'éditeur (cf. section Documentation)
    Check Point Spark Firewalls les pare-feux Spark versions R82.00.10 et antérieures sans les derniers correctifs de sécurité, se référer aux bulletins de sécurité de l'éditeur (cf. section Documentation)
    Check Point Security Gateways Security Gateways versions R81.20 et antérieures sans les derniers correctifs de sécurité, se référer aux bulletins de sécurité de l'éditeur (cf. section Documentation)
    Check Point Security Gateways Security Gateways versions R82 et antérieures sans les derniers correctifs de sécurité, se référer aux bulletins de sécurité de l'éditeur (cf. section Documentation)
    Check Point Spark Firewalls les pare-feux Spark versions R80.20.X
    Check Point Spark Firewalls les pare-feux Spark versions R81.10.17 et antérieures sans les derniers correctifs de sécurité, se référer aux bulletins de sécurité de l'éditeur (cf. section Documentation)
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Security Gateways version R81",
          "product": {
            "name": "Security Gateways",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Security Gateways version R81.10",
          "product": {
            "name": "Security Gateways",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Security Gateways version R80.40",
          "product": {
            "name": "Security Gateways",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Security Gateways versions R82.10 et ant\u00e9rieures sans les derniers correctifs de s\u00e9curit\u00e9, se r\u00e9f\u00e9rer aux bulletins de s\u00e9curit\u00e9 de l\u0027\u00e9diteur (cf. section Documentation)",
          "product": {
            "name": "Security Gateways",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "les pare-feux Spark versions R82.00.10 et ant\u00e9rieures sans les derniers correctifs de s\u00e9curit\u00e9, se r\u00e9f\u00e9rer aux bulletins de s\u00e9curit\u00e9 de l\u0027\u00e9diteur (cf. section Documentation)",
          "product": {
            "name": "Spark Firewalls",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Security Gateways versions R81.20 et ant\u00e9rieures sans les derniers correctifs de s\u00e9curit\u00e9, se r\u00e9f\u00e9rer aux bulletins de s\u00e9curit\u00e9 de l\u0027\u00e9diteur (cf. section Documentation)",
          "product": {
            "name": "Security Gateways",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Security Gateways versions R82 et ant\u00e9rieures sans les derniers correctifs de s\u00e9curit\u00e9, se r\u00e9f\u00e9rer aux bulletins de s\u00e9curit\u00e9 de l\u0027\u00e9diteur (cf. section Documentation)",
          "product": {
            "name": "Security Gateways",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "les pare-feux Spark versions R80.20.X",
          "product": {
            "name": "Spark Firewalls",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "les pare-feux Spark versions R81.10.17 et ant\u00e9rieures sans les derniers correctifs de s\u00e9curit\u00e9, se r\u00e9f\u00e9rer aux bulletins de s\u00e9curit\u00e9 de l\u0027\u00e9diteur (cf. section Documentation)",
          "product": {
            "name": "Spark Firewalls",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "L\u0027\u00e9diteur pr\u00e9cise que les versions R80.40, R81 et R81.10 de Security Gateways ainsi que les versions R80.20.X des pare-feux Spark sont en fin de vie et ne recevront donc pas de correctif.",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-50752",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-50752"
        },
        {
          "name": "CVE-2026-50751",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-50751"
        }
      ],
      "initial_release_date": "2026-06-09T00:00:00",
      "last_revision_date": "2026-06-09T00:00:00",
      "links": [
        {
          "title": "Billet de blogue Check Point",
          "url": "https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/"
        }
      ],
      "reference": "CERTFR-2026-AVI-0711",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-06-09T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les VPN Check Point. Elles permettent \u00e0 un attaquant de provoquer un contournement de la politique de s\u00e9curit\u00e9.\n\nCheck Point indique que la vuln\u00e9rabilit\u00e9 CVE-2026-50751 est activement exploit\u00e9e.\n\nLa vuln\u00e9rabilit\u00e9 CVE-2026-50751 affecte les instances avec le protocole IKEv1 activ\u00e9.\n\nL\u0027\u00e9diteur fournit \u00e9galement des mesures de contournement ainsi que des indicateurs de compromission. Ceux-ci n\u0027ont pas \u00e9t\u00e9 qualifi\u00e9s par le CERT-FR.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans les VPN Check Point",
      "vendor_advisories": [
        {
          "published_at": "2026-06-08",
          "title": "Bulletin de s\u00e9curit\u00e9 Check Point sk185033",
          "url": "https://support.checkpoint.com/results/sk/sk185033"
        },
        {
          "published_at": "2026-06-08",
          "title": "Bulletin de s\u00e9curit\u00e9 Check Point sk185035",
          "url": "https://support.checkpoint.com/results/sk/sk185035"
        }
      ]
    }

    CERTFR-2026-AVI-0650

    Vulnerability from certfr_avis - Published: 2026-05-27 - Updated: 2026-05-27

    De multiples vulnérabilités ont été découvertes dans les produits Check Point. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    Check Point Security Gateways Security Gateways versions R82.10 sans le correctif 19
    Check Point Security Gateways Security Gateways versions R81.20 sans le correctif 141
    Check Point Security Gateways Security Gateways versions R82 sans le correctif 103
    Check Point Spark Firewalls Spark Firewalls versions R81 antérieures à R81.10.17
    Check Point Spark Firewalls Spark Firewalls versions R82 antérieures à R82.00.10
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Security Gateways versions R82.10 sans le correctif 19",
          "product": {
            "name": "Security Gateways",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Security Gateways versions R81.20 sans le correctif 141",
          "product": {
            "name": "Security Gateways",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Security Gateways versions R82 sans le correctif 103",
          "product": {
            "name": "Security Gateways",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Spark Firewalls versions R81 ant\u00e9rieures \u00e0 R81.10.17",
          "product": {
            "name": "Spark Firewalls",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        },
        {
          "description": "Spark Firewalls versions R82 ant\u00e9rieures \u00e0 R82.00.10",
          "product": {
            "name": "Spark Firewalls",
            "vendor": {
              "name": "Check Point",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-48135",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-48135"
        },
        {
          "name": "CVE-2026-48136",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-48136"
        },
        {
          "name": "CVE-2026-48134",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-48134"
        },
        {
          "name": "CVE-2026-48131",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-48131"
        },
        {
          "name": "CVE-2026-48132",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-48132"
        },
        {
          "name": "CVE-2026-48133",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-48133"
        }
      ],
      "initial_release_date": "2026-05-27T00:00:00",
      "last_revision_date": "2026-05-27T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-0650",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-05-27T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        },
        {
          "description": "Injection SQL (SQLi)"
        },
        {
          "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits Check Point. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer un d\u00e9ni de service \u00e0 distance, une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es et une atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits Check Point",
      "vendor_advisories": [
        {
          "published_at": "2026-05-26",
          "title": "Bulletin de s\u00e9curit\u00e9 Check Point sk184983",
          "url": "https://support.checkpoint.com/results/sk/sk184983"
        },
        {
          "published_at": "2026-05-26",
          "title": "Bulletin de s\u00e9curit\u00e9 Check Point sk184992",
          "url": "https://support.checkpoint.com/results/sk/sk184992"
        },
        {
          "published_at": "2026-05-26",
          "title": "Bulletin de s\u00e9curit\u00e9 Check Point sk184993",
          "url": "https://support.checkpoint.com/results/sk/sk184993"
        },
        {
          "published_at": "2026-05-26",
          "title": "Bulletin de s\u00e9curit\u00e9 Check Point sk184991",
          "url": "https://support.checkpoint.com/results/sk/sk184991"
        },
        {
          "published_at": "2026-05-26",
          "title": "Bulletin de s\u00e9curit\u00e9 Check Point sk184981",
          "url": "https://support.checkpoint.com/results/sk/sk184981"
        },
        {
          "published_at": "2026-05-26",
          "title": "Bulletin de s\u00e9curit\u00e9 Check Point sk184982",
          "url": "https://support.checkpoint.com/results/sk/sk184982"
        }
      ]
    }

    CVE-2024-6233 (GCVE-0-2024-6233)

    Vulnerability from nvd – Published: 2024-11-22 20:05 – Updated: 2024-11-22 20:55
    VLAI
    Title
    Check Point ZoneAlarm Extreme Security Link Following Local Privilege Escalation Vulnerability
    Summary
    Check Point ZoneAlarm Extreme Security Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Check Point ZoneAlarm Extreme Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Forensic Recorder service. By creating a symbolic link, an attacker can abuse the service to overwrite arbitrary files. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-21677.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-11-22 20:43 UTC
    CWE
    • CWE-59 - Improper Link Resolution Before File Access ('Link Following')
    References
    Impacted products
    Vendor Product Version
    Check Point ZoneAlarm Extreme Security Affected: 4.0.148.0
    Create a notification for this product.
    check_point zonealarm_extreme_security Affected: 4.0.148.0
        cpe:2.3:a:check_point:zonealarm_extreme_security:4.0.148.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-07-31 21:19
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:check_point:zonealarm_extreme_security:4.0.148.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "zonealarm_extreme_security",
                "vendor": "check_point",
                "versions": [
                  {
                    "status": "affected",
                    "version": "4.0.148.0"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-6233",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-22T20:43:03.859640Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-22T20:55:29.976Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "ZoneAlarm Extreme Security",
              "vendor": "Check Point",
              "versions": [
                {
                  "status": "affected",
                  "version": "4.0.148.0"
                }
              ]
            }
          ],
          "dateAssigned": "2024-06-20T21:51:41.939Z",
          "datePublic": "2024-07-31T21:19:51.078Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Check Point ZoneAlarm Extreme Security Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Check Point ZoneAlarm Extreme Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the Forensic Recorder service. By creating a symbolic link, an attacker can abuse the service to overwrite arbitrary files. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-21677."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.0"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-59",
                  "description": "CWE-59: Improper Link Resolution Before File Access (\u0027Link Following\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-11-22T20:05:39.766Z",
            "orgId": "99f1926a-a320-47d8-bbb5-42feb611262e",
            "shortName": "zdi"
          },
          "references": [
            {
              "name": "ZDI-24-1036",
              "tags": [
                "x_research-advisory"
              ],
              "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1036/"
            }
          ],
          "source": {
            "lang": "en",
            "value": "Filip Dragovic (@filip_dragovic)"
          },
          "title": "Check Point ZoneAlarm Extreme Security Link Following Local Privilege Escalation Vulnerability"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "99f1926a-a320-47d8-bbb5-42feb611262e",
        "assignerShortName": "zdi",
        "cveId": "CVE-2024-6233",
        "datePublished": "2024-11-22T20:05:39.766Z",
        "dateReserved": "2024-06-20T21:51:41.913Z",
        "dateUpdated": "2024-11-22T20:55:29.976Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-8463 (GCVE-0-2019-8463)

    Vulnerability from nvd – Published: 2019-12-23 18:18 – Updated: 2024-08-04 21:17
    VLAI
    Summary
    A denial of service vulnerability was reported in Check Point Endpoint Security Client for Windows before E82.10, that could allow service log file to be written to non-standard locations.
    Severity
    No CVSS data available.
    CWE
    • CWE-59 - Improper Link Resolution Before File Access ('Link Following')
    References
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T21:17:31.349Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://supportcontent.checkpoint.com/solutions?id=sk163578"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Check Point Endpoint Security Client for Windows",
              "vendor": "Check Point",
              "versions": [
                {
                  "status": "affected",
                  "version": "before E82.10"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A denial of service vulnerability was reported in Check Point Endpoint Security Client for Windows before E82.10, that could allow service log file to be written to non-standard locations."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-59",
                  "description": "CWE-59: Improper Link Resolution Before File Access (\u0027Link Following\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-12-23T18:18:50.000Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://supportcontent.checkpoint.com/solutions?id=sk163578"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@checkpoint.com",
              "ID": "CVE-2019-8463",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Check Point Endpoint Security Client for Windows",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "before E82.10"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Check Point"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A denial of service vulnerability was reported in Check Point Endpoint Security Client for Windows before E82.10, that could allow service log file to be written to non-standard locations."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-59: Improper Link Resolution Before File Access (\u0027Link Following\u0027)"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://supportcontent.checkpoint.com/solutions?id=sk163578",
                  "refsource": "CONFIRM",
                  "url": "https://supportcontent.checkpoint.com/solutions?id=sk163578"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2019-8463",
        "datePublished": "2019-12-23T18:18:50.000Z",
        "dateReserved": "2019-02-18T00:00:00.000Z",
        "dateUpdated": "2024-08-04T21:17:31.349Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-8459 (GCVE-0-2019-8459)

    Vulnerability from nvd – Published: 2019-06-20 16:50 – Updated: 2024-08-04 21:17
    VLAI
    Summary
    Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the path. This can cause loading of a previously placed executable with a name similar to the parts of the path, instead of the intended one.
    Severity
    No CVSS data available.
    CWE
    References
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T21:17:31.581Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=\u0026solutionid=sk124972#Resolved%20Issues"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Check Point Endpoint Security Client for Windows, VPN blade",
              "vendor": "Check Point",
              "versions": [
                {
                  "status": "affected",
                  "version": "before E80.83"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the path. This can cause loading of a previously placed executable with a name similar to the parts of the path, instead of the intended one."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-428",
                  "description": "CWE-428",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-06-20T16:50:58.000Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=\u0026solutionid=sk124972#Resolved%20Issues"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@checkpoint.com",
              "ID": "CVE-2019-8459",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Check Point Endpoint Security Client for Windows, VPN blade",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "before E80.83"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Check Point"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the path. This can cause loading of a previously placed executable with a name similar to the parts of the path, instead of the intended one."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-428"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=\u0026solutionid=sk124972#Resolved%20Issues",
                  "refsource": "CONFIRM",
                  "url": "https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=\u0026solutionid=sk124972#Resolved%20Issues"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2019-8459",
        "datePublished": "2019-06-20T16:50:58.000Z",
        "dateReserved": "2019-02-18T00:00:00.000Z",
        "dateUpdated": "2024-08-04T21:17:31.581Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-8458 (GCVE-0-2019-8458)

    Vulnerability from nvd – Published: 2019-06-20 16:44 – Updated: 2024-08-04 21:17
    VLAI
    Summary
    Check Point Endpoint Security Client for Windows, with Anti-Malware blade installed, before version E81.00, tries to load a non-existent DLL during an update initiated by the UI. An attacker with administrator privileges can leverage this to gain code execution within a Check Point Software Technologies signed binary, where under certain circumstances may cause the client to terminate.
    Severity
    No CVSS data available.
    CWE
    References
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T21:17:31.415Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=\u0026solutionid=sk153053"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Check Point Endpoint Security Client for Windows, Anti-Malware blade",
              "vendor": "Check Point",
              "versions": [
                {
                  "status": "affected",
                  "version": "before E81.00"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Check Point Endpoint Security Client for Windows, with Anti-Malware blade installed, before version E81.00, tries to load a non-existent DLL during an update initiated by the UI. An attacker with administrator privileges can leverage this to gain code execution within a Check Point Software Technologies signed binary, where under certain circumstances may cause the client to terminate."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-114",
                  "description": "CWE-114",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-06-20T16:44:33.000Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=\u0026solutionid=sk153053"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@checkpoint.com",
              "ID": "CVE-2019-8458",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Check Point Endpoint Security Client for Windows, Anti-Malware blade",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "before E81.00"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Check Point"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Check Point Endpoint Security Client for Windows, with Anti-Malware blade installed, before version E81.00, tries to load a non-existent DLL during an update initiated by the UI. An attacker with administrator privileges can leverage this to gain code execution within a Check Point Software Technologies signed binary, where under certain circumstances may cause the client to terminate."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-114"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=\u0026solutionid=sk153053",
                  "refsource": "CONFIRM",
                  "url": "https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=\u0026solutionid=sk153053"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2019-8458",
        "datePublished": "2019-06-20T16:44:33.000Z",
        "dateReserved": "2019-02-18T00:00:00.000Z",
        "dateUpdated": "2024-08-04T21:17:31.415Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-8454 (GCVE-0-2019-8454)

    Vulnerability from nvd – Published: 2019-04-29 15:10 – Updated: 2024-08-04 21:17
    VLAI
    Summary
    A local attacker can create a hard-link between a file to which the Check Point Endpoint Security client for Windows before E80.96 writes and another BAT file, then by impersonating the WPAD server, the attacker can write BAT commands into that file that will later be run by the user or the system.
    Severity
    No CVSS data available.
    CWE
    References
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T21:17:31.447Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://supportcenter.us.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=\u0026solutionid=sk150012"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Check Point Endpoint Security client for Windows",
              "vendor": "Check Point",
              "versions": [
                {
                  "status": "affected",
                  "version": "before E80.96"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A local attacker can create a hard-link between a file to which the Check Point Endpoint Security client for Windows before E80.96 writes and another BAT file, then by impersonating the WPAD server, the attacker can write BAT commands into that file that will later be run by the user or the system."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-65",
                  "description": "CWE-65,CWE-377",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-04-29T15:10:15.000Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://supportcenter.us.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=\u0026solutionid=sk150012"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@checkpoint.com",
              "ID": "CVE-2019-8454",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Check Point Endpoint Security client for Windows",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "before E80.96"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Check Point"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A local attacker can create a hard-link between a file to which the Check Point Endpoint Security client for Windows before E80.96 writes and another BAT file, then by impersonating the WPAD server, the attacker can write BAT commands into that file that will later be run by the user or the system."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-65,CWE-377"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://supportcenter.us.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=\u0026solutionid=sk150012",
                  "refsource": "MISC",
                  "url": "https://supportcenter.us.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=\u0026solutionid=sk150012"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2019-8454",
        "datePublished": "2019-04-29T15:10:15.000Z",
        "dateReserved": "2019-02-18T00:00:00.000Z",
        "dateUpdated": "2024-08-04T21:17:31.447Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-8456 (GCVE-0-2019-8456)

    Vulnerability from nvd – Published: 2019-04-09 20:44 – Updated: 2024-08-04 21:17
    VLAI
    Summary
    Check Point IKEv2 IPsec VPN up to R80.30, in some less common conditions, may allow an attacker with knowledge of the internal configuration and setup to successfully connect to a site-to-site VPN server.
    Severity
    No CVSS data available.
    CWE
    References
    Impacted products
    Date Public
    2019-04-08 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T21:17:31.589Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=\u0026solutionid=sk149892"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Check Point IPsec VPN",
              "vendor": "Check Point",
              "versions": [
                {
                  "status": "affected",
                  "version": "Up to R80.30"
                }
              ]
            }
          ],
          "datePublic": "2019-04-08T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Check Point IKEv2 IPsec VPN up to R80.30, in some less common conditions, may allow an attacker with knowledge of the internal configuration and setup to successfully connect to a site-to-site VPN server."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-284",
                  "description": "CWE-284",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-04-09T20:44:32.000Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=\u0026solutionid=sk149892"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@checkpoint.com",
              "ID": "CVE-2019-8456",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Check Point IPsec VPN",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Up to R80.30"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Check Point"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Check Point IKEv2 IPsec VPN up to R80.30, in some less common conditions, may allow an attacker with knowledge of the internal configuration and setup to successfully connect to a site-to-site VPN server."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-284"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=\u0026solutionid=sk149892",
                  "refsource": "MISC",
                  "url": "https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=\u0026solutionid=sk149892"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2019-8456",
        "datePublished": "2019-04-09T20:44:32.000Z",
        "dateReserved": "2019-02-18T00:00:00.000Z",
        "dateUpdated": "2024-08-04T21:17:31.589Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-6233 (GCVE-0-2024-6233)

    Vulnerability from cvelistv5 – Published: 2024-11-22 20:05 – Updated: 2024-11-22 20:55
    VLAI
    Title
    Check Point ZoneAlarm Extreme Security Link Following Local Privilege Escalation Vulnerability
    Summary
    Check Point ZoneAlarm Extreme Security Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Check Point ZoneAlarm Extreme Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Forensic Recorder service. By creating a symbolic link, an attacker can abuse the service to overwrite arbitrary files. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-21677.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-11-22 20:43 UTC
    CWE
    • CWE-59 - Improper Link Resolution Before File Access ('Link Following')
    References
    Impacted products
    Vendor Product Version
    Check Point ZoneAlarm Extreme Security Affected: 4.0.148.0
    Create a notification for this product.
    check_point zonealarm_extreme_security Affected: 4.0.148.0
        cpe:2.3:a:check_point:zonealarm_extreme_security:4.0.148.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-07-31 21:19
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:check_point:zonealarm_extreme_security:4.0.148.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "zonealarm_extreme_security",
                "vendor": "check_point",
                "versions": [
                  {
                    "status": "affected",
                    "version": "4.0.148.0"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-6233",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-22T20:43:03.859640Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-22T20:55:29.976Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "ZoneAlarm Extreme Security",
              "vendor": "Check Point",
              "versions": [
                {
                  "status": "affected",
                  "version": "4.0.148.0"
                }
              ]
            }
          ],
          "dateAssigned": "2024-06-20T21:51:41.939Z",
          "datePublic": "2024-07-31T21:19:51.078Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Check Point ZoneAlarm Extreme Security Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Check Point ZoneAlarm Extreme Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the Forensic Recorder service. By creating a symbolic link, an attacker can abuse the service to overwrite arbitrary files. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-21677."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.0"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-59",
                  "description": "CWE-59: Improper Link Resolution Before File Access (\u0027Link Following\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-11-22T20:05:39.766Z",
            "orgId": "99f1926a-a320-47d8-bbb5-42feb611262e",
            "shortName": "zdi"
          },
          "references": [
            {
              "name": "ZDI-24-1036",
              "tags": [
                "x_research-advisory"
              ],
              "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1036/"
            }
          ],
          "source": {
            "lang": "en",
            "value": "Filip Dragovic (@filip_dragovic)"
          },
          "title": "Check Point ZoneAlarm Extreme Security Link Following Local Privilege Escalation Vulnerability"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "99f1926a-a320-47d8-bbb5-42feb611262e",
        "assignerShortName": "zdi",
        "cveId": "CVE-2024-6233",
        "datePublished": "2024-11-22T20:05:39.766Z",
        "dateReserved": "2024-06-20T21:51:41.913Z",
        "dateUpdated": "2024-11-22T20:55:29.976Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-8463 (GCVE-0-2019-8463)

    Vulnerability from cvelistv5 – Published: 2019-12-23 18:18 – Updated: 2024-08-04 21:17
    VLAI
    Summary
    A denial of service vulnerability was reported in Check Point Endpoint Security Client for Windows before E82.10, that could allow service log file to be written to non-standard locations.
    Severity
    No CVSS data available.
    CWE
    • CWE-59 - Improper Link Resolution Before File Access ('Link Following')
    References
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T21:17:31.349Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://supportcontent.checkpoint.com/solutions?id=sk163578"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Check Point Endpoint Security Client for Windows",
              "vendor": "Check Point",
              "versions": [
                {
                  "status": "affected",
                  "version": "before E82.10"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A denial of service vulnerability was reported in Check Point Endpoint Security Client for Windows before E82.10, that could allow service log file to be written to non-standard locations."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-59",
                  "description": "CWE-59: Improper Link Resolution Before File Access (\u0027Link Following\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-12-23T18:18:50.000Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://supportcontent.checkpoint.com/solutions?id=sk163578"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@checkpoint.com",
              "ID": "CVE-2019-8463",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Check Point Endpoint Security Client for Windows",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "before E82.10"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Check Point"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A denial of service vulnerability was reported in Check Point Endpoint Security Client for Windows before E82.10, that could allow service log file to be written to non-standard locations."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-59: Improper Link Resolution Before File Access (\u0027Link Following\u0027)"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://supportcontent.checkpoint.com/solutions?id=sk163578",
                  "refsource": "CONFIRM",
                  "url": "https://supportcontent.checkpoint.com/solutions?id=sk163578"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2019-8463",
        "datePublished": "2019-12-23T18:18:50.000Z",
        "dateReserved": "2019-02-18T00:00:00.000Z",
        "dateUpdated": "2024-08-04T21:17:31.349Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-8459 (GCVE-0-2019-8459)

    Vulnerability from cvelistv5 – Published: 2019-06-20 16:50 – Updated: 2024-08-04 21:17
    VLAI
    Summary
    Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the path. This can cause loading of a previously placed executable with a name similar to the parts of the path, instead of the intended one.
    Severity
    No CVSS data available.
    CWE
    References
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T21:17:31.581Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=\u0026solutionid=sk124972#Resolved%20Issues"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Check Point Endpoint Security Client for Windows, VPN blade",
              "vendor": "Check Point",
              "versions": [
                {
                  "status": "affected",
                  "version": "before E80.83"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the path. This can cause loading of a previously placed executable with a name similar to the parts of the path, instead of the intended one."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-428",
                  "description": "CWE-428",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-06-20T16:50:58.000Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=\u0026solutionid=sk124972#Resolved%20Issues"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@checkpoint.com",
              "ID": "CVE-2019-8459",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Check Point Endpoint Security Client for Windows, VPN blade",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "before E80.83"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Check Point"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the path. This can cause loading of a previously placed executable with a name similar to the parts of the path, instead of the intended one."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-428"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=\u0026solutionid=sk124972#Resolved%20Issues",
                  "refsource": "CONFIRM",
                  "url": "https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=\u0026solutionid=sk124972#Resolved%20Issues"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2019-8459",
        "datePublished": "2019-06-20T16:50:58.000Z",
        "dateReserved": "2019-02-18T00:00:00.000Z",
        "dateUpdated": "2024-08-04T21:17:31.581Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-8458 (GCVE-0-2019-8458)

    Vulnerability from cvelistv5 – Published: 2019-06-20 16:44 – Updated: 2024-08-04 21:17
    VLAI
    Summary
    Check Point Endpoint Security Client for Windows, with Anti-Malware blade installed, before version E81.00, tries to load a non-existent DLL during an update initiated by the UI. An attacker with administrator privileges can leverage this to gain code execution within a Check Point Software Technologies signed binary, where under certain circumstances may cause the client to terminate.
    Severity
    No CVSS data available.
    CWE
    References
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T21:17:31.415Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=\u0026solutionid=sk153053"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Check Point Endpoint Security Client for Windows, Anti-Malware blade",
              "vendor": "Check Point",
              "versions": [
                {
                  "status": "affected",
                  "version": "before E81.00"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Check Point Endpoint Security Client for Windows, with Anti-Malware blade installed, before version E81.00, tries to load a non-existent DLL during an update initiated by the UI. An attacker with administrator privileges can leverage this to gain code execution within a Check Point Software Technologies signed binary, where under certain circumstances may cause the client to terminate."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-114",
                  "description": "CWE-114",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-06-20T16:44:33.000Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=\u0026solutionid=sk153053"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@checkpoint.com",
              "ID": "CVE-2019-8458",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Check Point Endpoint Security Client for Windows, Anti-Malware blade",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "before E81.00"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Check Point"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Check Point Endpoint Security Client for Windows, with Anti-Malware blade installed, before version E81.00, tries to load a non-existent DLL during an update initiated by the UI. An attacker with administrator privileges can leverage this to gain code execution within a Check Point Software Technologies signed binary, where under certain circumstances may cause the client to terminate."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-114"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=\u0026solutionid=sk153053",
                  "refsource": "CONFIRM",
                  "url": "https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=\u0026solutionid=sk153053"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2019-8458",
        "datePublished": "2019-06-20T16:44:33.000Z",
        "dateReserved": "2019-02-18T00:00:00.000Z",
        "dateUpdated": "2024-08-04T21:17:31.415Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-8454 (GCVE-0-2019-8454)

    Vulnerability from cvelistv5 – Published: 2019-04-29 15:10 – Updated: 2024-08-04 21:17
    VLAI
    Summary
    A local attacker can create a hard-link between a file to which the Check Point Endpoint Security client for Windows before E80.96 writes and another BAT file, then by impersonating the WPAD server, the attacker can write BAT commands into that file that will later be run by the user or the system.
    Severity
    No CVSS data available.
    CWE
    References
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T21:17:31.447Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://supportcenter.us.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=\u0026solutionid=sk150012"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Check Point Endpoint Security client for Windows",
              "vendor": "Check Point",
              "versions": [
                {
                  "status": "affected",
                  "version": "before E80.96"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A local attacker can create a hard-link between a file to which the Check Point Endpoint Security client for Windows before E80.96 writes and another BAT file, then by impersonating the WPAD server, the attacker can write BAT commands into that file that will later be run by the user or the system."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-65",
                  "description": "CWE-65,CWE-377",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-04-29T15:10:15.000Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://supportcenter.us.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=\u0026solutionid=sk150012"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@checkpoint.com",
              "ID": "CVE-2019-8454",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Check Point Endpoint Security client for Windows",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "before E80.96"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Check Point"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A local attacker can create a hard-link between a file to which the Check Point Endpoint Security client for Windows before E80.96 writes and another BAT file, then by impersonating the WPAD server, the attacker can write BAT commands into that file that will later be run by the user or the system."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-65,CWE-377"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://supportcenter.us.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=\u0026solutionid=sk150012",
                  "refsource": "MISC",
                  "url": "https://supportcenter.us.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=\u0026solutionid=sk150012"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2019-8454",
        "datePublished": "2019-04-29T15:10:15.000Z",
        "dateReserved": "2019-02-18T00:00:00.000Z",
        "dateUpdated": "2024-08-04T21:17:31.447Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-8456 (GCVE-0-2019-8456)

    Vulnerability from cvelistv5 – Published: 2019-04-09 20:44 – Updated: 2024-08-04 21:17
    VLAI
    Summary
    Check Point IKEv2 IPsec VPN up to R80.30, in some less common conditions, may allow an attacker with knowledge of the internal configuration and setup to successfully connect to a site-to-site VPN server.
    Severity
    No CVSS data available.
    CWE
    References
    Impacted products
    Date Public
    2019-04-08 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T21:17:31.589Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=\u0026solutionid=sk149892"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Check Point IPsec VPN",
              "vendor": "Check Point",
              "versions": [
                {
                  "status": "affected",
                  "version": "Up to R80.30"
                }
              ]
            }
          ],
          "datePublic": "2019-04-08T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Check Point IKEv2 IPsec VPN up to R80.30, in some less common conditions, may allow an attacker with knowledge of the internal configuration and setup to successfully connect to a site-to-site VPN server."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-284",
                  "description": "CWE-284",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-04-09T20:44:32.000Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=\u0026solutionid=sk149892"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@checkpoint.com",
              "ID": "CVE-2019-8456",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Check Point IPsec VPN",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Up to R80.30"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Check Point"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Check Point IKEv2 IPsec VPN up to R80.30, in some less common conditions, may allow an attacker with knowledge of the internal configuration and setup to successfully connect to a site-to-site VPN server."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-284"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=\u0026solutionid=sk149892",
                  "refsource": "MISC",
                  "url": "https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=\u0026solutionid=sk149892"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2019-8456",
        "datePublished": "2019-04-09T20:44:32.000Z",
        "dateReserved": "2019-02-18T00:00:00.000Z",
        "dateUpdated": "2024-08-04T21:17:31.589Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }