CVE-2012-2753
Last modified
CVE-2012-2753 is a vulnerability of currently unknown severity. Untrusted search path vulnerability in TrGUI.exe in the Endpoint Connect (aka EPC) GUI in Check Point Endpoint Security R73.x and E80.x on the VPN blade platform, Endpoint Security VPN R75, Endpoint Connect R73.x, and Remote Access Clients E75.x allows local users to gain privileges via a Trojan horse DLL in the current working directory.. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
Untrusted search path vulnerability in TrGUI.exe in the Endpoint Connect (aka EPC) GUI in Check Point Endpoint Security R73.x and E80.x on the VPN blade platform, Endpoint Security VPN R75, Endpoint Connect R73.x, and Remote Access Clients E75.x allows local users to gain privileges via a Trojan horse DLL in the current working directory.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Checkpoint | Endpoint Connect | r73 |
| Checkpoint | Endpoint Security | e80 |
| Checkpoint | Endpoint Security | e80.10 |
| Checkpoint | Endpoint Security | e80.20 |
| Checkpoint | Endpoint Security | e80.30 |
| Checkpoint | Endpoint Security | r73 |
| Checkpoint | Endpoint Security Vpn | r75 |
| Checkpoint | Remote Access Clients | e75 |
| Checkpoint | Remote Access Clients | e75.10 |
| Checkpoint | Remote Access Clients | e75.20 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-2753?
How severe is CVE-2012-2753?
How do I fix CVE-2012-2753?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2012
- CVE-2012-2747Unspecified vulnerability in Joomla! 2.5.x before 2.5.5 allo…
- CVE-2012-2748Unspecified vulnerability in Joomla! 2.5.x before 2.5.5 allo…
- CVE-2012-2749MySQL 5.1.x before 5.1.63 and 5.5.x before 5.5.24 allows rem…
- CVE-2012-2750Unspecified vulnerability in MySQL 5.5.x before 5.5.23 has u…
- CVE-2012-2751ModSecurity before 2.6.6, when used with PHP, does not prope…
- CVE-2012-2752Untrusted search path vulnerability in VMware vMA 4.x and 5.…
- CVE-2012-2759Cross-site scripting (XSS) vulnerability in login-with-ajax.…
- CVE-2012-2760mod_auth_openid before 0.7 for Apache uses world-readable pe…
- CVE-2012-2762SQL injection vulnerability in include/functions_trackbacks.…
- CVE-2012-2763Buffer overflow in the readstr_upto function in plug-ins/scr…
- CVE-2012-2764Untrusted search path vulnerability in Google Chrome before …
- CVE-2012-2768Multiple cross-site scripting (XSS) vulnerabilities in the t…
Are you affected by CVE-2012-2753?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
