CVE-2022-23742CWE-65

Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory with low privileges

High · published May 12, 2022

CVSS v3.1
7.8
EPSS
4%
Percentile
90.1
In the wild
Unconfirmed
What it is

Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory with low privileges. An attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on unpatched systems or using symbolic links.

The record
Technical detail
CVSS v3.1
7.8 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.04109 · 90.1th percentile
Weakness
CWE-65 · Windows Hard Link
Published
2022-05-12T19:23Z
EPSS history
Timeline
  • 12 MAY 19:23Z
    Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory with low privileges
    cvelistv5