CVE-2019-8458: Medium severity checkpoint endpoint security vpn vulnerability
Check Point Endpoint Security Client for Windows, with Anti-Malware blade installed, before version E81.00, tries to load a non-existent DLL during an update initiated by the UI. An attacker with administrator privileges can leverage this to gain code execution within a Check Point Software Technologies signed binary, where under certain circumstances may cause the client to terminate.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-8458.
What is the severity of CVE-2019-8458?
The severity of CVE-2019-8458 is medium with a severity value of 4.4.
Which software is affected by CVE-2019-8458?
Check Point Endpoint Security Clients, Check Point Remote Access Clients, and Check Point Capsule Docs are affected by CVE-2019-8458.
How can an attacker leverage CVE-2019-8458?
An attacker with administrator privileges can leverage CVE-2019-8458 to gain code execution within a Check Point Software Technology product.
How can I fix CVE-2019-8458?
Update the Check Point Endpoint Security Client for Windows to version E81.00 or higher to fix CVE-2019-8458.