CVE-2019-6145: High severity forcepoint vulnerability
Forcepoint VPN Client for Windows versions lower than 6.6.1 have an unquoted search path vulnerability. This enables local privilege escalation to SYSTEM user. By default, only local administrators can write executables to the vulnerable directories. Forcepoint thanks Peleg Hadar of SafeBreach Labs for finding this vulnerability and for reporting it to us.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-6145?
CVE-2019-6145 is a vulnerability in Forcepoint VPN Client for Windows versions lower than 6.6.1 that allows local privilege escalation to the SYSTEM user.
How severe is CVE-2019-6145?
CVE-2019-6145 has a severity value of 6.7, which is considered high.
How can I fix CVE-2019-6145?
To fix CVE-2019-6145, update your Forcepoint VPN Client to version 6.6.1 or higher.
Who discovered CVE-2019-6145?
CVE-2019-6145 was discovered by Peleg Hadar of SafeBreach Labs.
What is the Common Weakness Enumeration (CWE) for CVE-2019-6145?
The Common Weakness Enumeration (CWE) for CVE-2019-6145 is CWE-428.