CVE-2022-23742
Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory with low privileges. An attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on unpatched systems or using symbolic links.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.8
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.09%
- CWE
- CWE-65
- Published
- 2022-05-12
- Last modified
- 2026-06-02
Affected products
- n/a Check Point Endpoint Security Client for Windows
Weakness type
Related vulnerabilities
- CVE-2026-70019 — Windows Compressed Folder Information Disclosure Vulnerability
- CVE-2020-6013 — ZoneAlarm Firewall and Antivirus products before version 15.8.109.18436 allow an attacker who...
- CVE-2019-19231 — An insecure file access vulnerability exists in CA Client Automation 14.0, 14.1, 14.2, and 14.3...
- CVE-2019-8454 — A local attacker can create a hard-link between a file to which the Check Point Endpoint Security...
- CVE-2019-8452 — A hard-link created from log file archive of Check Point ZoneAlarm up to 15.4.062 or Check Point...
- CVE-2019-8455 — A hard-link created from the log file of Check Point ZoneAlarm up to 15.4.062 to any file on the...