Endpoint Security

Vendor:

First CVE: Jun 19, 2012 · Active for 14 years

14
Total CVEs
More Total CVEs than 91% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 27% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Endpoint Security over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 19, 2012
14 years ago
Most Recent CVE
Nov 12, 2023
985 days ago

CVE Severity & Scoring

Endpoint Security14 CVEs
All CVEs352,294 CVEs
LowMediumHigh
Attack Vector
Local11 (78.6%)
Network0 (0.0%)
Unknown3 (21.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (71.4%)
High1 (7.1%)
Unknown3 (21.4%)
User Interaction
None8 (57.1%)
Unknown3 (21.4%)
Required3 (21.4%)
Privileges Required
Low7 (50.0%)
High2 (14.3%)
None2 (14.3%)
Unknown3 (21.4%)

Top CVEs

Signals from CVEs in this product scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A hard-link created from log file archive of Check Point ZoneAlarm up to 15.4.062 or Check Point Endpoint Security client for Windows before E80.96 to any file on the system will g
Apr 22, 20197.835NOYES
Users have access to the directory where the installation repair occurs. Since the MS Installer allows regular users to run the repair, an attacker can initiate the installation re
Jan 10, 20227.825NONO
Local privilege escalation in Check Point Endpoint Security Client (version E87.30) via crafted OpenSSL configuration file
Jul 23, 20237.824NONO
A local attacker can create a hard-link between a file to which the Check Point Endpoint Security client for Windows before E80.96 writes and another BAT file, then by impersonatin
Apr 29, 20197.023NONO
Local attacker can escalate privileges on affected installations of Check Point Harmony Endpoint/ZoneAlarm Extreme Security. An attacker must first obtain the ability to execute lo
Nov 12, 20237.822NONO
Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory with low privileges. An attacker can replace those f
May 12, 20227.821NONO
Check Point Endpoint Security Client for Windows before version E84.20 allows write access to the directory from which the installation repair takes place. Since the MS Installer a
Dec 3, 20207.820NONO
Check Point Endpoint Security Initial Client for Windows before version E81.30 tries to load a DLL placed in any PATH location on a clean image without Endpoint Client installed. A
Aug 29, 20197.820NONO
Untrusted search path vulnerability in TrGUI.exe in the Endpoint Connect (aka EPC) GUI in Check Point Endpoint Security R73.x and E80.x on the VPN blade platform, Endpoint Security
Jun 19, 20126.919NONO
Check Point Endpoint Security Client for Windows, with Anti-Bot or Threat Emulation blades installed, before version E83.20, tries to load a non-existent DLL during a query for the
Nov 2, 20206.517NONO

Exploit Exposure

Signals from CVEs in this product scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
7.1% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (14 CVEs).

Media Mentions

Signals from CVEs in this product scope (14 CVEs).

Top CNAs Publishing CVEs For Endpoint Security

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
r7316.90.4%00
e87.3017.85.6%00
e86.4012.34.3%00
e86.3012.34.3%00
e86.2012.34.3%00
e86.1012.34.3%00
e8617.80.2%00
e8525.02.3%00
e84.1015.50.3%00
e8425.02.3%00
e8312.34.3%00
e80.5023.30.2%00
e80.4123.30.2%00
e80.4023.30.2%00
e80.3034.50.3%00
e80.2034.50.3%00
e80.1034.50.3%00
e8034.50.3%00