Critical severity9.8NVD Advisory· Published Jun 20, 2019· Updated Jun 17, 2026
CVE-2019-8459
CVE-2019-8459
Description
Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the path. This can cause loading of a previously placed executable with a name similar to the parts of the path, instead of the intended one.
Affected products
9- cpe:2.3:a:checkpoint:capsule_docs_standalone_client:*:*:*:*:*:*:*:*Range: <e80.82
- cpe:2.3:a:checkpoint:endpoint_security_clients:*:*:*:*:*:windows:*:*Range: <e80.83
- cpe:2.3:a:checkpoint:endpoint_security_server_package:*:*:*:*:gaia:*:*:*Range: <r77.30.03
- cpe:2.3:a:checkpoint:jumbo_hotfix_for_endpoint_security_server:*:*:*:*:*:*:*:*Range: <r77.30
- cpe:2.3:a:checkpoint:remote_access_clients:*:*:*:*:*:windows:*:*Range: <e80.83
cpe:2.3:a:checkpoint:smartconsole_for_endpoint_security_server:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:checkpoint:smartconsole_for_endpoint_security_server:*:*:*:*:*:*:*:*range: <r77.30.03
- cpe:2.3:a:checkpoint:smartconsole_for_endpoint_security_server:e80.83:*:*:*:*:*:*:*
<E80.83+ 1 more
- (no CPE)range: <E80.83
- (no CPE)range: before E80.83
Patches
Vulnerability mechanics
References
1- supportcenter.checkpoint.com/supportcenter/portalnvdVendor Advisory
News mentions
0No linked articles in our index yet.