> Source: [sk179132](https://support.checkpoint.com/results/sk/sk179132)

# sk179132 - Check Point Response to CVE-2022-23742 - local privileges escalation in Endpoint Security Client's EFRService

| Property | Value |
|----------|-------|
| Solution ID | sk179132 |
| Date Created | 2022-05-11 |
| Last Modified | 2025-02-09 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |
| OS | Windows |

## Symptoms

- * The EFRService, which collects forensics data for various blades for the Check Point Endpoint Security Client for Windows, copies files for forensics reports from a directory with insufficient privileges. A local attacker can replace those files with malicious or linked content, which will run in higher privileges, as the Endpoint Client requires.

* This issue received the ID [CVE-2022-23742](https://www.cve.org/CVERecord?id=CVE-2022-23742).

## Solution

This problem was fixed. The fix is included starting from:

* **[Enterprise Endpoint Security E86.40 Windows Clients](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk178665)**

This issue was discovered and responsibly disclosed by Alain R�del of cirosec GmbH.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
