Vulnerability Details CVE-2019-8459
Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the path. This can cause loading of a previously placed executable with a name similar to the parts of the path, instead of the intended one.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 64.9%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2019-8459
-
cpe:2.3:a:checkpoint:capsule_docs_standalone_client:-
-
cpe:2.3:a:checkpoint:capsule_docs_standalone_client:e80.20
-
cpe:2.3:a:checkpoint:endpoint_security_clients:-
-
cpe:2.3:a:checkpoint:endpoint_security_server_package:*
-
cpe:2.3:a:checkpoint:jumbo_hotfix_for_endpoint_security_server:*
-
cpe:2.3:a:checkpoint:remote_access_clients:*
-
cpe:2.3:a:checkpoint:smartconsole_for_endpoint_security_server:*
-
cpe:2.3:a:checkpoint:smartconsole_for_endpoint_security_server:e80.83