Lucene search

K
cveCheckpointCVE-2021-30360
HistoryJan 10, 2022 - 2:10 p.m.

CVE-2021-30360

2022-01-1014:10:17
CWE-427
checkpoint
web.nvd.nist.gov
32
cve-2021-30360
directory access
ms installer
installation repair
unauthorized executable

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

17.8%

Users have access to the directory where the installation repair occurs. Since the MS Installer allows regular users to run the repair, an attacker can initiate the installation repair and place a specially crafted EXE in the repair folder which runs with the Check Point Remote Access Client privileges.

Affected configurations

Nvd
Node
checkpointendpoint_securityRange<e86.20windows
VendorProductVersionCPE
checkpointendpoint_security*cpe:2.3:a:checkpoint:endpoint_security:*:*:*:*:*:windows:*:*

CNA Affected

[
  {
    "product": "Check Point Remote Access Client",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "before E86.20"
      }
    ]
  }
]

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

17.8%

Related for CVE-2021-30360