Lucene search

K
cveCheckpointCVE-2023-28133
HistoryJul 23, 2023 - 10:15 a.m.

CVE-2023-28133

2023-07-2310:15:09
CWE-732
checkpoint
web.nvd.nist.gov
39
cve-2023-28133
local privilege escalation
check point endpoint security client
version e87.30
crafted openssl configuration file
nvd

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7.7

Confidence

High

EPSS

0.001

Percentile

22.6%

Local privilege escalation in Check Point Endpoint Security Client (version E87.30) via crafted OpenSSL configuration file

Affected configurations

Nvd
Node
checkpointendpoint_securityMatche87.30windows
VendorProductVersionCPE
checkpointendpoint_securitye87.30cpe:2.3:a:checkpoint:endpoint_security:e87.30:*:*:*:*:windows:*:*

CNA Affected

[
  {
    "product": "Harmony Endpoint.",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "E87.x before E81.31"
      }
    ]
  }
]

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7.7

Confidence

High

EPSS

0.001

Percentile

22.6%

Related for CVE-2023-28133