MEDIUM · 6.9

CVE-2012-2753

Untrusted search path vulnerability in TrGUI.exe in the Endpoint Connect (aka EPC) GUI in Check Point Endpoint Security R73.x and E80.x on the VPN blade platform, Endpoint Security VPN R75, Endpoint C...

Vulnerability Description

Untrusted search path vulnerability in TrGUI.exe in the Endpoint Connect (aka EPC) GUI in Check Point Endpoint Security R73.x and E80.x on the VPN blade platform, Endpoint Security VPN R75, Endpoint Connect R73.x, and Remote Access Clients E75.x allows local users to gain privileges via a Trojan horse DLL in the current working directory.

CVSS Score

6.9

MEDIUM

AV:L/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
CheckpointEndpoint Connectr73
CheckpointEndpoint Securitye80
CheckpointEndpoint Security Vpnr75
CheckpointRemote Access Clientse75

References

FAQ

What is CVE-2012-2753?

CVE-2012-2753 is a vulnerability with a CVSS score of 6.9 (MEDIUM). Untrusted search path vulnerability in TrGUI.exe in the Endpoint Connect (aka EPC) GUI in Check Point Endpoint Security R73.x and E80.x on the VPN blade platform, Endpoint Security VPN R75, Endpoint C...

How severe is CVE-2012-2753?

CVE-2012-2753 has been rated MEDIUM with a CVSS base score of 6.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-2753?

Check the references section above for vendor advisories and patch information. Affected products include: Checkpoint Endpoint Connect, Checkpoint Endpoint Security, Checkpoint Endpoint Security Vpn, Checkpoint Remote Access Clients.