Security Advisory

CVE-2020-6014

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-10-30 14:22:05
Last updated 2024-08-04 08:47:41
Assigner checkpoint
State PUBLISHED

Description

Check Point Endpoint Security Client for Windows, with Anti-Bot or Threat Emulation blades installed, before version E83.20, tries to load a non-existent DLL during a query for the Domain Name. An attacker with administrator privileges can leverage this to gain code execution within a Check Point Software Technologies signed binary, where under certain circumstances may cause the client to terminate.