Vulnerability Name: | CVE-2022-23742 (CCN-226496) | ||||||||||||
Assigned: | 2022-05-11 | ||||||||||||
Published: | 2022-05-11 | ||||||||||||
Updated: | 2022-05-23 | ||||||||||||
Summary: | Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory with low privileges. An attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on unpatched systems or using symbolic links. | ||||||||||||
CVSS v3 Severity: | 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-59 | ||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2022-23742 Source: XF Type: UNKNOWN checkpoint-cve202223742-priv-esc(226496) Source: CCN Type: Check Point ID sk179132 CVE-2022-23742 - Local Privileges Escalation in Check Point Endpoint Security Client's EFRService Source: MISC Type: Broken Link https://supportcontent.checkpoint.com/solutions?id=sk178665, Source: MISC Type: Vendor Advisory https://supportcontent.checkpoint.com/solutions?id=sk179132 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
BACK |