CVE-2025-8304

Information Disclosure in Identity Agent Registry Keys

Severity
Medium 6.5
CVSS 3.1
Exploited
Not listed
EPSS
0.001
2.0th percentile
Discovered by
Not disclosed
Published
Dec 22, 2025
Assigned by checkpoint

Description

An authenticated local user can obtain information that allows claiming security policy rules of another user due to sensitive information being accessible in the Windows Registry keys for Check Point Identity Agent running on a Terminal Server.

Weakness: CWE-200

Affected products

Vendor Product Category Matched by
Check Point Identity Agent Identity / IAM / MFA cna-assigner
Vendor-reported products (1)
  • checkpoint · Identity Agent

Something wrong here?