CVE-2019-8459: Check Point Capsule Docs Standalone Client
Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.
Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the path. This can cause loading of a previously placed executable with a name similar to the parts of the path, instead of the intended one.
Affected products
- Check Point Capsule Docs Standalone Client: before e80.82 (fixed in e80.82)
- Check Point Endpoint Security Clients: before e80.83 (fixed in e80.83)
- Check Point Endpoint Security Server Package: before r77.30.03 (fixed in r77.30.03)
- Check Point Jumbo Hotfix For Endpoint Security Server: before r77.30 (fixed in r77.30)
- Check Point Remote Access Clients: before e80.83 (fixed in e80.83)
- Check Point SmartConsole For Endpoint Security Server: before r77.30.03 (fixed in r77.30.03); version e80.83 only
Published 2019-06-20. Last modified 2026-06-17.