HIGH · 7.8

CVE-2022-23742

Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory with low privileges. An attacker can replace those files with malicious ...

Vulnerability Description

Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory with low privileges. An attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on unpatched systems or using symbolic links.

CVSS Score

7.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
CheckpointEndpoint Security< e86.40
MicrosoftWindows-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-23742?

CVE-2022-23742 is a vulnerability with a CVSS score of 7.8 (HIGH). Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory with low privileges. An attacker can replace those files with malicious ...

How severe is CVE-2022-23742?

CVE-2022-23742 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-23742?

Check the references section above for vendor advisories and patch information. Affected products include: Checkpoint Endpoint Security, Microsoft Windows.