7.8

CVE-2024-24916

DLL-HiJacking

Untrusted DLLs in the installer's directory may be loaded and executed, leading to potentially arbitrary code execution with the installer's privileges (admin).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Checkpoint ≫ Smartconsole Version r81.10 Update build400
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.10 Update build402
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.10 Update build404
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.10 Update build406
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.10 Update build407
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.10 Update build409
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.10 Update build410
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.10 Update build412
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.10 Update build413
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.10 Update build414
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.10 Update build416
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.10 Update build417
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.10 Update build418
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.10 Update build420
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.10 Update build423
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.10 Update build424
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.10 Update build425
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.20 Update build640
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.20 Update build641
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.20 Update build645
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.20 Update build646
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.20 Update build649
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.20 Update build651
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.20 Update build653
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.20 Update build654
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.20 Update build655
   Microsoft ≫ Windows Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.18% 0.809
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Checkpoint 6.5 0.6 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
CWE-427 Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

https://support.checkpoint.com/results/sk/sk183342
Vendor Advisory