CVE-2022-23742
HIGHCheck Point Endpoint Security Client for Windows < E86.40 - Privilege Escalation via Hard Link Attack
Title source: llmDescription
Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory with low privileges. An attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on unpatched systems or using symbolic links.
References (2)
Core 2
Core References
Various Sources x_refsource_misc
https://supportcontent.checkpoint.com/solutions?id=sk178665%2C
Vendor Advisory x_refsource_misc
https://supportcontent.checkpoint.com/solutions?id=sk179132
Scores
CVSS v3
7.8
EPSS
0.0408
EPSS Percentile
89.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-59
CWE-65
Status
published
Products (2)
None/Check Point Endpoint Security Client for Windows
before E86.40
checkpoint/endpoint_security
< e86.40
Published
May 12, 2022
Tracked Since
Feb 18, 2026