Check Point VPN-1 SecureClient Path Specification Local Privilege Escalation Vulnerability
BID:16290
Info
Check Point VPN-1 SecureClient Path Specification Local Privilege Escalation Vulnerability
| Bugtraq ID: | 16290 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 17 2006 12:00AM |
| Updated: | Jan 17 2006 12:00AM |
| Credit: | Thierry Zoller <[email protected]> discovered this issue. |
| Vulnerable: |
Check Point Software VPN-1 4.1 SP6 Check Point Software VPN-1 4.1 SP5a Check Point Software VPN-1 4.1 SP5 Check Point Software VPN-1 4.1 SP4 Check Point Software VPN-1 4.1 SP3 Check Point Software VPN-1 4.1 SP2 Check Point Software VPN-1 4.1 SP1 Check Point Software VPN-1 4.1 Check Point Software VPN-1 FP1 |
| Not Vulnerable: | |
Discussion
Check Point VPN-1 SecureClient Path Specification Local Privilege Escalation Vulnerability
Check Point VPN-1 SecureClient is prone to a vulnerability that could allow an arbitrary file to be executed.
The application attempts to execute an application without using properly quoted paths. Successful exploitation may allow local attackers to gain elevated privileges.
Specific information about affected versions of Check Point VPN-1 SecureClient is unavailable at this time. This BID will be updated as further information is disclosed.
Check Point VPN-1 SecureClient is prone to a vulnerability that could allow an arbitrary file to be executed.
The application attempts to execute an application without using properly quoted paths. Successful exploitation may allow local attackers to gain elevated privileges.
Specific information about affected versions of Check Point VPN-1 SecureClient is unavailable at this time. This BID will be updated as further information is disclosed.
Exploit / POC
Check Point VPN-1 SecureClient Path Specification Local Privilege Escalation Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Check Point VPN-1 SecureClient Path Specification Local Privilege Escalation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Check Point VPN-1 SecureClient Path Specification Local Privilege Escalation Vulnerability
References:
References:
- VPN-1 Clients (Check Point Software)
- [ TZO-012006 ] Checkpoint VPN-1 SecureClient insecure usage of CreateProcess() (Thierry Zoller
)