> Source: [sk181276](https://support.checkpoint.com/results/sk/sk181276)

# sk181276 - Check Point Response to CVE-2023-28133 - Local privilege escalation in Check Point Endpoint Security Client via crafted OpenSSL configuration file

| Property | Value |
|----------|-------|
| Solution ID | sk181276 |
| Date Created | 2023-07-19 |
| Last Modified | 2025-02-09 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |
| OS | Windows |

## Symptoms

- Local privilege escalation in Check Point Endpoint Security Client.

Affected versions: E87.30 and lower, including all E86.x clients.

Affected clients: Standalone Remote Access VPN clients, Endpoint Security Clients with Remote Access VPN enabled.

Affected processes: `TracSrvWrapper.exe`, `epab_svc.exe`, `cpinfo_uploader.exe`, `cpda.exe`, `cpinfo.exe`, `IDAFServerHostService.exe`

Attack vector is via custom crafted OpenSSL configuration file allowing local privilege escalation in some situations, allowing a low privileged account (member of the Users group) to execute arbitrary commands.

This issue received the ID [CVE-2023-28133](https://www.cve.org/CVERecord?id=CVE-2023-28133).

## Solution

This problem was fixed. The fix is included starting from:

* [Enterprise Endpoint Security E87.31 (E87.30 Hotfix) Windows Clients](https://support.checkpoint.com/results/sk/sk181206)

The telemetry library has been updated in this fix and does not use the open *openssl.cnf* file.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
