> Source: [sk175968](https://support.checkpoint.com/results/sk/sk175968)

# sk175968 - Check Point Response to CVE-2021-30359 - Harmony Browse installer or SandBlast Agent for Browsers installer can be used for privileges escalation

| Property | Value |
|----------|-------|
| Solution ID | sk175968 |
| Date Created | 2021-10-20 |
| Last Modified | 2025-02-09 |
| Technical Level | General |
| Products | Browser - Classic |
| Versions | Cloud |
| OS | Windows |

## Symptoms

- * When executing Harmony Browse or SandBlast Agent for Browsers installer locally with user-level privileges, it was possible to get administrator privileges on the endpoint computer
* This issue exists only in client version lower than 90.08.7405
* This issue is documented as [CVE-2021-30359](https://www.cve.org/CVERecord?id=CVE-2021-30359)

## Cause

The Harmony Browse and the SandBlast Agent for Browsers installers must have admin privileges to execute some steps during the installation. Because the MS Installer let regular users to repair their installation, an attacker running the old version of the installer can start the installation repair and place a specially crafted binary in the repair folder, which runs with the admin privileges.

Therefore, it was possible to abuse the installer and execute other scripts with admin privileges, even without admin permissions on the endpoint.

## Solution

A new version of the Harmony Browse and SandBlast Agent for Browser installers was published, which does not allow execution without admin privileges. The new version of the installer is therefore not exposed to this vulnerability.  
Administrators should download the new installer from the [Check Point Infinity Portal](https://portal.checkpoint.com/).

You must make sure your installer version is 90.08.7405 and above. In order to determine the current installer version, click on Computer Management on the left and review the Agent Version column.   

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk175968/pic1202111140957091.jpg)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
