CVE-2024-24916

MEDIUM

Installer - Code Injection

Title source: llm
STIX 2.1

Description

Untrusted DLLs in the installer's directory may be loaded and executed, leading to potentially arbitrary code execution with the installer's privileges (admin).

Scores

CVSS v3 6.5
EPSS 0.0011
EPSS Percentile 29.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-427
Status published
Products (2)
checkpoint/smartconsole r81.10 build400 (17 CPE variants)
checkpoint/smartconsole r81.20 build640 (9 CPE variants)
Published Jun 19, 2025
Tracked Since Feb 18, 2026