CVE-2019-8454
A local attacker can create a hard-link between a file to which the Check Point Endpoint Security client for Windows before E80.96 writes and another BAT file, then by impersonating the WPAD server, the attacker can write BAT commands into that file that will later be run by the user or the system.
Scoring
- CVSS base score
- 0
- EPSS probability
- 0.03%
- CWE
- CWE-65
- Published
- 2019-04-29
- Last modified
- 2026-03-14
Affected products
- Check Point Check Point Endpoint Security client for Windows
Weakness type
Related vulnerabilities
- CVE-2026-70019 — Windows Compressed Folder Information Disclosure Vulnerability
- CVE-2022-23742 — Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for...
- CVE-2020-6013 — ZoneAlarm Firewall and Antivirus products before version 15.8.109.18436 allow an attacker who...
- CVE-2019-19231 — An insecure file access vulnerability exists in CA Client Automation 14.0, 14.1, 14.2, and 14.3...
- CVE-2019-8452 — A hard-link created from log file archive of Check Point ZoneAlarm up to 15.4.062 or Check Point...
- CVE-2019-8455 — A hard-link created from the log file of Check Point ZoneAlarm up to 15.4.062 to any file on the...