CVE-2012-2753

UnknownEPSS 0.40%

Last modified

CVE-2012-2753 is a vulnerability of currently unknown severity. Untrusted search path vulnerability in TrGUI.exe in the Endpoint Connect (aka EPC) GUI in Check Point Endpoint Security R73.x and E80.x on the VPN blade platform, Endpoint Security VPN R75, Endpoint Connect R73.x, and Remote Access Clients E75.x allows local users to gain privileges via a Trojan horse DLL in the current working directory.. EPSS estimates a 0.40% chance of exploitation in the next 30 days.

Description

Untrusted search path vulnerability in TrGUI.exe in the Endpoint Connect (aka EPC) GUI in Check Point Endpoint Security R73.x and E80.x on the VPN blade platform, Endpoint Security VPN R75, Endpoint Connect R73.x, and Remote Access Clients E75.x allows local users to gain privileges via a Trojan horse DLL in the current working directory.

Metrics

EPSS Probability
0.40%

31.6th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
CheckpointEndpoint Connectr73
CheckpointEndpoint Securitye80
CheckpointEndpoint Securitye80.10
CheckpointEndpoint Securitye80.20
CheckpointEndpoint Securitye80.30
CheckpointEndpoint Securityr73
CheckpointEndpoint Security Vpnr75
CheckpointRemote Access Clientse75
CheckpointRemote Access Clientse75.10
CheckpointRemote Access Clientse75.20

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2012-2753?
Untrusted search path vulnerability in TrGUI.exe in the Endpoint Connect (aka EPC) GUI in Check Point Endpoint Security R73.x and E80.x on the VPN blade platform, Endpoint Security VPN R75, Endpoint Connect R73.x, and Remote Access Clients E75.x allows local users to gain privileges via a Trojan horse DLL in the current working directory.
How severe is CVE-2012-2753?
Severity scoring for CVE-2012-2753 is pending analysis. The EPSS model estimates a 0.40% probability of exploitation in the next 30 days.
How do I fix CVE-2012-2753?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2012-2753?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST