Check Point SSL VPN On-Demand Applications Remote Code Execution Vulnerability
RISK: High Risk
TYPE: Security software and application - Security Software & Appliance
A vulnerability has been identified in Check Point products, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an error in the SSL Network Extender (SNX), SecureWorkSpace and Endpoint Security On-Demand application when deployed through a browser, which could allow attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.
Impact
- Remote Code Execution
System / Technologies affected
- Check Point SecurePlatform
- Check Point IPSO6
- Check Point Connectra
- Check Point VSX
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Apply patches:
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk62410
Vulnerability Identifier
Source
Related Link
Share with