CVE-2025-8304
Information Disclosure in Identity Agent Registry Keys
Severity
Medium 6.5
CVSS 3.1
Exploited
Not listed
EPSS
0.001
2.0th percentile
Discovered by
Not disclosed
Published
Dec 22, 2025
Assigned by checkpoint
Description
An authenticated local user can obtain information that allows claiming security policy rules of another user due to sensitive information being accessible in the Windows Registry keys for Check Point Identity Agent running on a Terminal Server.
Weakness: CWE-200
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Check Point | Identity Agent | Identity / IAM / MFA | cna-assigner |
Vendor-reported products (1)
- checkpoint · Identity Agent