CVE-2025-9142
7.5Check Point · Harmony SASE Windows Agent
A path traversal vulnerability in the Check Point Harmony SASE Windows Agent allows local users to write or delete files outside the intended certificate directory.
Executive summary
A path traversal vulnerability in the Check Point Harmony SASE Windows Agent permits local attackers to perform unauthorized file operations, posing a significant risk to system integrity.
Vulnerability
The software contains a path traversal flaw (CWE-22) that allows a local user with low privileges to manipulate files outside of the designated certificate working directory. The attack requires the user to have local access to the system.
Business impact
The ability for an unprivileged local user to write or delete arbitrary files can lead to complete system compromise, including the potential for privilege escalation or the destruction of critical system data. Given the CVSS score of 7.5, this vulnerability represents a high risk to business operations, as it could facilitate the installation of malicious payloads or the disruption of security-sensitive configurations.
Remediation
Immediate Action: Update the Check Point Harmony SASE Windows Agent to version 12.2 or later to resolve the underlying path traversal issue.
Proactive Monitoring: Review system logs for unauthorized file modification attempts or unexpected process execution patterns originating from the SASE agent.
Compensating Controls: Restrict local user permissions on the host system to minimize the potential for non-administrative users to execute unauthorized software or access restricted directories.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability presents a high risk to endpoints running the affected Harmony SASE agent. Organizations should prioritize the deployment of version 12.2 across their Windows fleet. In environments where immediate patching is not feasible, restrict local user access to the maximum extent possible to mitigate the risk of local exploitation.
More Check Point CVEs
History
- Disclosed CVE record published
- Published in the daily brief high section
- Analyst report written