CVE-2024-24912

Local privilege escalation in Harmony Endpoint Security Client for Windows via crafted DLL file

Severity
Medium 6.7
CVSS 3.1
Exploited
Not listed
EPSS
0.002
5.6th percentile
Discovered by
Not disclosed
Published
May 1, 2024
Assigned by checkpoint

Description

A local privilege escalation vulnerability has been identified in Harmony Endpoint Security Client for Windows versions E88.10 and below. To exploit this vulnerability, an attacker must first obtain the ability to execute local privileged code on the target system.

Weakness: CWE-732

Affected products

Vendor Product Category Matched by
Check Point Harmony Endpoint Endpoint / EDR cna-assigner
Vendor-reported products (2)
  • checkpoint · Harmony Endpoint Security Client for Windows
  • checkpoint · harmony_endpoint

Credit

Kolja Grassmann (Cirosec GmbH)

Something wrong here?