CVE-2019-8461: High severity checkpoint capsule docs vulnerability
Check Point Endpoint Security Initial Client for Windows before version E81.30 tries to load a DLL placed in any PATH location on a clean image without Endpoint Client installed. An attacker can leverage this to gain LPE using a specially crafted DLL placed in any PATH location accessible with write permissions to the user.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-8461?
CVE-2019-8461 is a vulnerability in Check Point Endpoint Security Initial Client for Windows before version E81.30 that allows an attacker to gain local privilege escalation.
What is the severity of CVE-2019-8461?
CVE-2019-8461 has a severity rating of 7.8 out of 10 (high severity).
How does CVE-2019-8461 work?
CVE-2019-8461 allows an attacker to load a specially crafted DLL placed in any accessible PATH location, which can lead to local privilege escalation.
Which software versions are affected by CVE-2019-8461?
Check Point Endpoint Security Initial Client for Windows versions before E81.30 are affected by CVE-2019-8461.
How can I mitigate the CVE-2019-8461 vulnerability?
To mitigate the CVE-2019-8461 vulnerability, it is recommended to update Check Point Endpoint Security Initial Client for Windows to version E81.30 or later.