> Source: [sk181597](https://support.checkpoint.com/results/sk/sk181597)

# sk181597 - Local Privilege Escalation in Check Point Endpoint Security Remediation Service

| Property | Value |
|----------|-------|
| Solution ID | sk181597 |
| Date Created | 2023-11-07 |
| Last Modified | 2025-01-15 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |
| OS | Windows |

## Symptoms

- This vulnerability allows local attackers to escalate privileges on affected installations of Check Point Harmony Endpoint / ZoneAlarm Extreme Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Remediation Service. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.

## Solution

This issue was discovered and responsibly disclosed by Filip Dragovic working with Trend Micro Zero Day Initiative and received the ID [CVE-2023-28134](https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-28134).

This problem was fixed. The fix is included starting from:

* [Enterprise Endpoint Security E87.10 Windows Clients](https://support.checkpoint.com/results/sk/sk180420)
* [Zone Alarm Extreme Security NextGen version 4.2.510 and later](https://www.zonealarm.com/software/extreme-security-nextgen/release-history)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
