Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-6021

Опубликовано: 03 дек. 2020
Источник: nvd
CVSS3: 7.8
CVSS2: 4.4
EPSS Низкий

Описание

Check Point Endpoint Security Client for Windows before version E84.20 allows write access to the directory from which the installation repair takes place. Since the MS Installer allows regular users to run the repair, an attacker can initiate the installation repair and place a specially crafted DLL in the repair folder which will run with the Endpoint client’s privileges.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:checkpoint:endpoint_security:*:*:*:*:*:windows:*:*
Версия до e84.20 (исключая)

EPSS

Процентиль: 18%
0.00058
Низкий

7.8 High

CVSS3

4.4 Medium

CVSS2

Дефекты

CWE-427
CWE-427

Связанные уязвимости

github
больше 3 лет назад

Check Point Endpoint Security Client for Windows before version E84.20 allows write access to the directory from which the installation repair takes place. Since the MS Installer allows regular users to run the repair, an attacker can initiate the installation repair and place a specially crafted DLL in the repair folder which will run with the Endpoint client’s privileges.

EPSS

Процентиль: 18%
0.00058
Низкий

7.8 High

CVSS3

4.4 Medium

CVSS2

Дефекты

CWE-427
CWE-427