logo

Check Point Harmony SASE Windows Client Vulnerability Enables Privilege Escalation

ID: a177396f-d1a3-5562-a068-8f627f66af97

STIX ID: report--a177396f-d1a3-5562-a068-8f627f66af97

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-01-28

Date Updated: 2026-04-21

Author: Abinaya

...
...

A local privilege-escalation vulnerability (CVE-2025-9142) in Check Point Harmony SASE Windows client (Perimeter81.Service.exe) allows attackers to bypass JWT validation and use directory traversal plus symbolic-link injection to write malicious DLLs to protected system locations and achieve SYSTEM-level execution; Check Point published a fix in version 12.2 and affected customers are advised to upgrade immediately and apply local hardening (restrict admin rights, application whitelisting).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.