CVE-2019-8459: Critical severity checkpoint endpoint security server vulnerability
Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the path. This can cause loading of a previously placed executable with a name similar to the parts of the path, instead of the intended one.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2019-8459.
What is the severity level of CVE-2019-8459?
The severity level of CVE-2019-8459 is critical with a score of 9.8.
Which software versions are affected by CVE-2019-8459?
The affected software versions are Check Point Endpoint Security Client for Windows with the VPN blade before version E80.83.
What is the impact of CVE-2019-8459?
CVE-2019-8459 can cause loading of a previously placed executable with a name similar to the parts of the path, instead of the intended one.
Is there a fix available for CVE-2019-8459?
Yes, a fix is available for CVE-2019-8459. Refer to the Check Point support website for more information.