CVE-2024-24910: Check Point Identity Agent

High severity, CVSS 7.3. EPSS: 0.2% chance of exploitation in the next 30 days.

A local attacker can erscalate privileges on affected Check Point ZoneAlarm ExtremeSecurity NextGen, Identity Agent for Windows, and Identity Agent for Windows Terminal Server. To exploit this vulnerability, an attacker must first obtain the ability to execute local privileged code on the target system.

Affected products

  • Check Point Identity Agent: up to and including r81.070.0000
  • Check Point Zonealarm Extreme Security NextGen: before 4.2.712 (fixed in 4.2.712)

Published 2024-04-18. Last modified 2026-06-17.