Executive brief
A security vulnerability exists in the Check Point Identity Agent, a tool used to identify users on corporate networks for security policy enforcement. A person with basic access to a Windows computer could exploit this flaw to gain full administrative control (SYSTEM privileges) over that machine. This could allow an attacker to bypass security controls, access sensitive local data, or install malicious software.
Technical details
A local privilege escalation vulnerability (CWE-427: Uncontrolled Search Path Element) exists in the Check Point Identity Agent Full for Windows. The flaw resides in the log collection process, where the application improperly handles executable resolution, allowing for potential DLL hijacking or path redirection. An authenticated local attacker with low privileges can exploit this to execute arbitrary code with SYSTEM-level authority. The vulnerability requires local access but no user interaction. Check Point has addressed this in advisory sk185052.
Affected products
- Check Point Identity Agent Full Windows OS versions prior to fix
Timeline
- 2026-06-11: disclosed
- 2026-06-11: advisory