checkpoint endpoint-security CVE-2021-30360 is a vulnerability in Check Point Software Endpoint Security
Published on January 10, 2022

Users have access to the directory where the installation repair occurs. Since the MS Installer allows regular users to run the repair, an attacker can initiate the installation repair and place a specially crafted EXE in the repair folder which runs with the Check Point Remote Access Client privileges.

NVD

Weakness Type

What is a DLL preloading Vulnerability?

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

CVE-2021-30360 has been classified to as a DLL preloading vulnerability or weakness.


Products Associated with CVE-2021-30360

Want to know whenever a new CVE is published for Check Point Software Endpoint Security? stack.watch will email you.

 

Exploit Probability

EPSS
0.13%
Percentile
31.93%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.