CVE-2025-9142

Local privilege escalation in Harmony SASE Windows Agent

Severity
High 7.5
CVSS 3.1
Exploited
Not listed
EPSS
0.001
0.2th percentile
Discovered by
Not disclosed
Published
Jan 14, 2026
Assigned by checkpoint

Description

A local user can trigger Harmony SASE Windows client to write or delete files outside the intended certificate working directory.

Weakness: CWE-22

Affected products

Vendor Product Category Matched by
Check Point Harmony SASE SASE / SSE / Secure Web cna-assigner
Vendor-reported products (1)
  • checkpoint · Hramony SASE

Something wrong here?