CVE-2025-9142 describes a path traversal vulnerability (CWE-22) in the Harmony SASE Windows client, allowing a local, low-privileged user to write or delete files outside the intended directory. This vulnerability carries a CVSS score of 7.5 (HIGH), indicating a significant impact on confidentiality, integrity, and availability, albeit requiring user interaction and high attack complexity. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Checkpoint | Hramony SASE | Check Point Harmony SASE Windows Agent versions prior to 12.2CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.2 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.5 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.