CVE-2019-8459: Check Point Capsule Docs Standalone Client

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the path. This can cause loading of a previously placed executable with a name similar to the parts of the path, instead of the intended one.

Affected products

  • Check Point Capsule Docs Standalone Client: before e80.82 (fixed in e80.82)
  • Check Point Endpoint Security Clients: before e80.83 (fixed in e80.83)
  • Check Point Endpoint Security Server Package: before r77.30.03 (fixed in r77.30.03)
  • Check Point Jumbo Hotfix For Endpoint Security Server: before r77.30 (fixed in r77.30)
  • Check Point Remote Access Clients: before e80.83 (fixed in e80.83)
  • Check Point SmartConsole For Endpoint Security Server: before r77.30.03 (fixed in r77.30.03); version e80.83 only

Published 2019-06-20. Last modified 2026-06-17.