CVE-2019-8461: Check Point Capsule Docs Standalone Client

High severity, CVSS 7.8. EPSS: 1.1% chance of exploitation in the next 30 days.

Check Point Endpoint Security Initial Client for Windows before version E81.30 tries to load a DLL placed in any PATH location on a clean image without Endpoint Client installed. An attacker can leverage this to gain LPE using a specially crafted DLL placed in any PATH location accessible with write permissions to the user.

Affected products

  • Check Point Capsule Docs Standalone Client: before e80.20 (fixed in e80.20)
  • Check Point Endpoint Security: before e81.30 (fixed in e81.30)
  • Check Point Remote Access Clients: before e81.30 (fixed in e81.30)

Published 2019-08-29. Last modified 2026-06-17.