Vulnerability Description
Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory with low privileges. An attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on unpatched systems or using symbolic links.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Checkpoint | Endpoint Security | < e86.40 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://supportcontent.checkpoint.com/solutions?id=sk178665%2C
- https://supportcontent.checkpoint.com/solutions?id=sk179132Vendor Advisory
- https://supportcontent.checkpoint.com/solutions?id=sk178665%2C
- https://supportcontent.checkpoint.com/solutions?id=sk179132Vendor Advisory
FAQ
What is CVE-2022-23742?
CVE-2022-23742 is a vulnerability with a CVSS score of 7.8 (HIGH). Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory with low privileges. An attacker can replace those files with malicious ...
How severe is CVE-2022-23742?
CVE-2022-23742 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-23742?
Check the references section above for vendor advisories and patch information. Affected products include: Checkpoint Endpoint Security, Microsoft Windows.