Vulnerability record · CVE-2020-6021 · published 3 December 2020
CVE-2020-6021: Checkpoint endpoint security uncontrolled search path element vulnerability
Checkpoint · Endpoint Security
Check Point Endpoint Security Client for Windows before version E84.20 allows write access to the directory from which the installation repair takes place. Since the MS Installer allows regular users to run the repair, an attacker can initiate the installation repair and place a specially crafted DLL in the repair folder which will run with the Endpoint client’s privileges.
Description
Check Point Endpoint Security Client for Windows before version E84.20 allows write access to the directory from which the installation repair takes place. Since the MS Installer allows regular users to run the repair, an attacker can initiate the installation repair and place a specially crafted DLL in the repair folder which will run with the Endpoint client’s privileges.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://supportcontent.checkpoint.com/solutions?id=sk170512 | Vendor Advisory |
| https://supportcontent.checkpoint.com/solutions?id=sk170512 | Vendor Advisory |
Track CVE-2020-6021 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-6021), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.