Executive brief
Check Point Security Management and Log Servers are critical infrastructure components used to centrally manage firewall policies and store security logs for organizations. A stack overflow vulnerability in the unauthenticated login process allows remote attackers to execute arbitrary code with root privileges, potentially giving attackers full control over the security management infrastructure and access to sensitive security logs.
Technical details
The vulnerability is a stack overflow in the login process of Check Point Security Management and Log Servers that can be triggered during unauthenticated access. The stack overflow occurs before authentication is completed, meaning no valid credentials are required to exploit it. A remote network attacker can exploit this vulnerability to achieve arbitrary code execution with root privileges on the affected servers. The attack vector is network-based and does not require user interaction or prior authentication.
Affected products
- Check Point Security Management Server
- Check Point Log Server
Timeline
- 2026-09-16: disclosed