CVE-2021-30360
Summary
| CVE | CVE-2021-30360 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-10 14:10:00 UTC |
| Updated | 2022-01-14 16:43:00 UTC |
| Description | Users have access to the directory where the installation repair occurs. Since the MS Installer allows regular users to run the repair, an attacker can initiate the installation repair and place a specially crafted EXE in the repair folder which runs with the Check Point Remote Access Client privileges. |
Risk And Classification
Problem Types: CWE-427
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Checkpoint | Endpoint Security | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Enterprise Endpoint Security E86.20 Windows Clients | MISC | supportcontent.checkpoint.com | |
| Vulnerability-Disclosures/MNDT-2022-0001.md at master · mandiant/Vulnerability-Disclosures · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.