> Source: [sk182244](https://support.checkpoint.com/results/sk/sk182244)

# sk182244 - Check Point Response to CVE-2024-24912 - local privilege escalation in Harmony Endpoint Security Client for Windows via crafted DLL file

| Property | Value |
|----------|-------|
| Solution ID | sk182244 |
| Date Created | 2024-04-25 |
| Last Modified | 2025-02-09 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | E88.X |
| OS | Windows |

## Symptoms

- A local privilege escalation vulnerability has been identified in Harmony Endpoint Security Client for Windows versions E88.10 and lower.

By manipulating the COM object, an attacker could load a specially crafted DLL.

An attacker must first obtain the ability to execute local privileged code on the target system in order to exploit this vulnerability.

An attacker can leverage this vulnerability to compromising the integrity and confidentiality of the system.

This issue received the ID [CVE-2024-24912](https://www.cve.org/CVERecord?id=CVE-2024-24912).

## Solution

This problem was fixed. The fix is included starting from:

* [Enterprise Endpoint Security E88.20 Windows Clients](https://support.checkpoint.com/results/sk/sk182044)

The issue was discovered by Kolja Grassmann (Cirosec GmbH) and Alain R�del (Neodyme).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
