> Source: [sk183380](https://support.checkpoint.com/results/sk/sk183380)

# sk183380 - Enterprise Endpoint Security E88.72 (E88.70 Hotfix) Windows Clients

| Property | Value |
|----------|-------|
| Solution ID | sk183380 |
| Date Created | 2025-04-21 |
| Last Modified | 2026-08-09 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | E88.X |
| OS | Windows |

## Solution

|------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------|
| * **In a Nutshell** * **Resolved Issues** * **Endpoint Security Client Downloads** | * **Standalone Client Downloads** * **Endpoint Security Server Downloads** * **Management Console Downloads** | * **Utilities/Services Downloads** * **Known Limitations** * **Documentation \& Related SK Articles** |

<br />

**Notes:**

* See **[Endpoint Security Homepage.](https://support.checkpoint.com/results/sk/sk117536)**
* **This Hotfix complements the E88.70 release with important fixes.**
* This release includes all limitations of earlier releases unless explicitly shown as resolved.

<br />

Click Here to Show the Entire Article  
<br />

In a Nutshell {#1}
------------------

|----------------------------------------------|-------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------|
| Item                                         | Description                                                       | Download Link                                                                                                            |
| **Managed Client - US-DHS and EU compliant** | E88.72 Endpoint Security Clients for Windows OS - Dynamic package | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/137878) (EXE) |
| **Managed Client - US-DHS and EU compliant** | E88.72 Endpoint Security Clients for Windows OS - Initial Client  | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/137879) (ZIP) |
| For more info about replacing Anti-Malware Blade with US-DHS and EU compliant Blade, refer to [sk178307](https://support.checkpoint.com/results/sk/sk178307).                                                                             |||
| **VPN Standalone Client**                    | E88.72 Remote Access VPN Clients for Windows                      | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/141832) (MSI) |

List of Resolved Issues in E88.72 for Windows {#3}
--------------------------------------------------

<br />

{#Infrastructure}{#Infrastructure}{#Infrastructure}

|------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| ID         | Description                                                                                                                                                                                                                               |
| General                                                                                                                                                                                                                                               ||
| AHTP-32939 | After an upgrade to E88.70, the *CPFileAnlyz* process exits unexpectedly, causing the Anti-Malware and File Protection Blades to crash.                                                                                                   |
| EPS-59933  | A memory leak in IDAFServerHostService.exe occurs after the *CPDA* process exits during periods of high network activity, resulting in DAF memory consumption increasing to 1GB.                                                          |
| EPS-59936  | Endpoint client does not receive correct policies because of file corruption.                                                                                                                                                             |
| EPS-59935  | Endpoint Security Client connectivity is unstable when using a direct connection to the Security Management Server if there is an extensive list of Super Nodes without any specific Super Node configured in the Client Settings policy. |
| EPS-59934  | When a computer is simultaneously joined to both a Legacy Domain and an Azure Domain, the Domain membership information is not accurately reflected in the Harmony Management Portal.                                                     |
| Anti-Ransomware and Forensics                                                                                                                                                                                                                         ||
| AHTP-32968 | Anti-Malware Scan Interface (AMSI) mechanism is unstable.                                                                                                                                                                                 |
| AHTP-32941 | Anti-Ransomware backup exceeds the configured maximum disk size limit.                                                                                                                                                                    |
| EPS-59943  | Some applications such as Microsoft Office may crash or be unresponsive when an Endpoint Security add-on is installed.                                                                                                                    |
| Firewall and Application Control                                                                                                                                                                                                                      ||
| EPS-59939  | A potential crash in *vsmon.exe* may occur when writing an entry to the log file, this causes the Firewall and Application Control Blade to appear as not running.                                                                        |

{#3}  

Endpoint Security Client Downloads {#4}
---------------------------------------

Show / Hide this section  
> * Starting from E80.85, Harmony Endpoint improves coverage of malicious threats by sending anonymized Incident related data to the Check Point Threat Cloud. This feature is turned on by default. For more information, including how to disable this feature, refer to [sk129753](https://support.checkpoint.com/results/sk/sk129753).
>
> ### *Endpoint Security E88.72 Clients - US-DHS and EU compliant* {#Endpoint_Security_E85.10_ClientsE2}
>
> |-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------|
> | Package Description                                                                                                                                                                                                                                                                                             | Links                                                                                                                                                                                                                                             ||
> | Endpoint Security Clients for Windows OS - Dynamic package: > Complete Endpoint Security Client for any CPU (32bit or 64bit). This is a self-extracting executable EXE file with all components (Blades).                                                                                                       | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/137878) (EXE)                                                                                                                          ||
> | Initial client: > Initial client is a very thin client without any blade used for software deployment purposes.                                                                                                                                                                                                 | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/137879) (ZIP)                                                                                                                          ||
> | Package Description                                                                                                                                                                                                                                                                                             | 32bit                                                                                                                    | 64bit                                                                                                                   |
> | **Endpoint Complete package:** > * Anti-Bot and URL Filtering > * Anti-Malware > * Anti-Ransomware, Behavioral Guard and Forensics > * Compliance and Posture > * Firewall and Application Control > * Full Disk Encryption > * Media Encryption and Port Protection > * Threat Emulation > * Remote Access VPN | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/137880) (ZIP) | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/137881)(ZIP) |
>
> {#resolvedTable}   
For more info about replacing Anti-Malware Blade with US-DHS and EU compliant Blade, refer to [sk178307](https://support.checkpoint.com/results/sk/sk178307). {#Endpoint_Security_E85.10_Clients}  

Standalone Client Downloads {#5}
--------------------------------

Show / Hide this section  
**Note** : These Standalone clients do not require Endpoint Security Server installation as part of their deployment.  

### *Standalone E88.72 Clients* {#Toggle_Standalone_Clients}

**Note** : Remote Access VPN Standalone Client E88.70 is replaced with E88.72, which includes a stability improvement. Customers running Remote Access VPN Standalone Client E88.70 are advised to upgrade to E88.72. See the ESVPN-4784 issue in Known Limitations below.  

|----------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------|
| Package                                                        | Description                                                                                                                                                                         | Link                                                                                                                     |
| **Remote Access VPN Clients for Windows**                      | Remote Access VPN Client for SmartDashboard-managed clients                                                                                                                         | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/141832) (MSI) |
| **Remote Access VPN Clients (Automatic Upgrade file)**         | Remote Access VPN Client for automatic upgrade through the gateway. For SmartDashboard-managed clients only.                                                                        | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/141833) (CAB) |
| **Remote Access VPN Clients for ATM**                          | Unattended Remote Access VPN clients, managed with CLI and API and do not have a User interface.                                                                                    | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/141834) (MSI) |
| **Remote Access VPN Clients for ATM (Automatic Upgrade file)** | Unattended Remote Access VPN clients, managed with CLI and API and do not have a User interface for automatic upgrade through the gateway. For SmartDashboard-managed clients only. | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/141835) (CAB) |

{#resolvedTable}  

Endpoint Security Server Downloads {#6}
---------------------------------------

Show / Hide this section  
>
> |--------------------------|---------------------------------|----------------------------------------------------------------|
> | Endpoint Security Server | Package                         | Link                                                           |
> | **R82**                  | Endpoint Security Server R82    | [sk181127](https://support.checkpoint.com/results/sk/sk181127) |
> | **R81.20**               | Endpoint Security Server R81.20 | [sk173903](https://support.checkpoint.com/results/sk/sk173903) |
> | **R81.10**               | Endpoint Security Server R81.10 | [sk170416](https://support.checkpoint.com/results/sk/sk170416) |

> {#resolvedTable}

Management Console Downloads {#7}
---------------------------------

Show / Hide this section  
>
> ### *Management Console for Endpoint Security Server* {#SmartConsole for Endpoint Security Server}
>
> The SmartConsole for Endpoint Security Server allows the Administrator to connect to the Endpoint Security Server and to manage the new Endpoint Security Software Blades.
>
> |--------------------------|--------------------------------------------------|----------------------------------------------------------------------------------------------------------------|
> | Endpoint Security Server | Package                                          | Link                                                                                                           |
> | **R82**                  | SmartConsole for Endpoint Security Server R82    | [link](https://support.checkpoint.com/results/download/125531)                                                 |
> | **R81.20**               | SmartConsole for Endpoint Security Server R81.20 | [link](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20_SC/R81.20/R81.20-List-of-all-Resolved-Issues.htm) |
> | **R81.10**               | SmartConsole for Endpoint Security Server R81.10 | [link](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10_SC/Default.htm)                                   |

{#resolvedTable}  

Utilities Downloads {#8}
------------------------

Show / Hide this section  
>
> |-------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------|
> | Package                                                     | Description                                                                                                                                                                                                                                                                                                                                                        | Link                                                                                                                     |
> | **Harmony Endpoint Remediation Manager for Administrators** | The administrator utility contains the capabilities of the end-user utility plus these additional features: * Quarantine - Send files to quarantine. * Delete - Use the Harmony Endpoint remediation service to delete a file. * Import - Import a quarantined file from a different computer or location. Get the administrator utility from the release homepage | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/132854) (EXE) |
> | **Full Disk Encryption Offline Management Tool**            | The Endpoint Offline Management Tool lets administrators manage offline mode users and give them password recovery and disk recovery.                                                                                                                                                                                                                              | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/120236) (TGZ) |
> | **Full Disk Encryption Offline Management Tool (Japanese)** | The Endpoint Offline Management Tool lets administrators manage offline mode users and give them password recovery and disk recovery.                                                                                                                                                                                                                              | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/120237) (TGZ) |

{#resolvedTable} {#Full Disk Encryption Offline Management Tool}  

Known Limitations {#9}
----------------------

Show / Hide this section  
>
> |------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
> | Issue ID   | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
> | ESVPN-4784 | Remote Access VPN Standalone Client E88.70 is replaced with E88.72, which includes a stability improvement. Customers running Remote Access VPN Standalone Client E88.70 are advised to upgrade to E88.72.                                                                                                                                                                                                                                                                                                                                                                                                                 |
> | EPS-51129  | FDE Smart Pre-boot (EA feature) secondary external display connected via docking station may not work. Support for secondary display via docking stations is experimental and depends on hardware, firmware settings, and display connection type.                                                                                                                                                                                                                                                                                                                                                                         |
> | EPS-50963  | Endpoint Client Posture Management is not supported on Windows 7 OS. Automatic Download is not displayed, and the Patch status is shown as "*Update not available*".                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
> | EPS-51871  | When Windows Smart App Control is enabled, it blocks the execution of the Media Encryption offline utility (which is located on the removeable media). As a workaround, you can copy the utility *Access To Business Data.exe* to a local disk and execute it from there.                                                                                                                                                                                                                                                                                                                                                  |
> | EPS-52957  | SmartCard authentication is only supported in Legacy Pre-boot but it is not supported in FDE Smart Pre-boot (EA feature).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
> | ESVPN-3943 | The login prompt of Implicit Secure Domain Logon (SDL) appears before the Windows logon on the computer, which is not part of any domain.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
> | ESVPN-4305 | * If the user changes the language of the Endpoint Security Client UI, the language of the VPN UI will not be changed until the next reboot. * If the user changes the language of Endpoint Security Client UI to a non-Latin language (Russian, Greek, Chinese, etc.), he might see question marks in VPN UI unless he sets the correct language for non-Unicode applications in Windows language settings.                                                                                                                                                                                                               |
> | AHTP-30337 | For Endpoint Security Clients with Anti-Malware E2 (US-DHS and EU compliant), after an upgrade from E88.31 or lower to E88.40 or higher version: * On Windows machines that support Azure Code Signing Signatures, Check Point Endpoint Security is registered twice in the Windows Security Center. Reboot resolves the issue. * On Windows machines that do not support Azure Code Signing Signatures, after updating Windows with configuration and dependencies to support Azure Code Signing signatures, Check Point Endpoint Security is registered twice in the Windows Security Center. Reboot resolves the issue. |
> | EPS-58003  | In some scenarios, the transition from Classic Pre-boot to FDE Smart Pre-boot (EA feature) may require a restart.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |

Documentation \& Related SecureKnowledge Articles {#10}
-------------------------------------------------------

Show / Hide this section  
>
> |-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
> | Endpoint Security Clients                                                                                                                                                                       |
> | [Endpoint Security Clients for Windows E88.x Release Notes (English)](https://sc1.checkpoint.com/documents/E88.x/EN/Endpoint_Security_Clients_for_Windows_RN/Default.htm)                       |
> | [Endpoint Security Clients for Windows E88.x Release Notes (Japanese)](https://sc1.checkpoint.com/documents/E88.x/JP/Endpoint_Security_Clients_for_Windows_RN/Default.htm)                      |
> | [Endpoint Security Clients for Windows User Guide](https://sc1.checkpoint.com/documents/HarmonyEndpoint/Endpoint_Security_Clients_for_Windows_UserGuide/Default.htm)                            |
> | [Replacing Anti-Malware Blade with US-DHS and EU compliant Blade](https://support.checkpoint.com/results/sk/sk178307)                                                                           |
> | [Endpoint Security for Windows MDM Deployment Guide](https://sc1.checkpoint.com/documents/HarmonyEndpoint/Harmony_Endpoint_Security_for_Windows_MDM_Deployment_Guide/Default.htm)               |
> | [sk110420 - Endpoint Security Client Supported Upgrade Paths](https://support.checkpoint.com/results/sk/sk110420)                                                                               |
> | [sk120667 - How to upgrade to Windows 10 1607 and higher with FDE in-place](https://support.checkpoint.com/results/sk/sk120667)                                                                 |
> | [sk133174 - Enterprise Endpoint Security Windows Clients for ATM](https://support.checkpoint.com/results/sk/sk133174)                                                                           |
> | [sk182694 - Enterprise Endpoint Security Hotfixes for E88.x Windows Clients Releases](https://support.checkpoint.com/results/sk/sk182694)                                                       |
> | [Endpoint Security Safe Deployment Procedure (SDP)](https://sc1.checkpoint.com/documents/HarmonyEndpoint/Harmony_Endpoint_Safe_Deployment/Harmony_Endpoint_Safe_Deployment_Procedure_(SDP).pdf) |
> | Remote Access VPN Clients                                                                                                                                                                       |
> | [E88.x Remote Access VPN Clients for Windows Release Notes](https://sc1.checkpoint.com/documents/E88.x/EN/Remote_Access_VPN_Clients_for_Windows_RN/Default.htm)                                 |
> | [Remote Access VPN Clients for Windows Administration Guide](https://sc1.checkpoint.com/documents/RemoteAccessClients_forWindows_AdminGuide/Default.htm)                                        |
> | EPMaaS                                                                                                                                                                                          |
> | [Endpoint Security Administration Guide](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Default.htm)                                       |
> | Endpoint Security Server                                                                                                                                                                        |
> | [Endpoint Security Server R82 Administration Guide](https://sc1.checkpoint.com/documents/R82/SmartEndpoint_OLH/EN/Content/Topics-EPSG-R82.00/Intro-to-Endpoint_Security.htm)                    |
> | [Endpoint Security Web Management R82 Administration Guide](https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_HarmonyEndpointWebManagement_AdminGuide/Default.htm)              |
> | [R82 Release Notes](https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_RN/Default.htm)                                                                                           |
> | [Endpoint Security Server R81.20 Administration Guide](https://sc1.checkpoint.com/documents/R81.20/SmartEndpoint_OLH/EN/Default.htm)                                                            |
> | [Endpoint Security Web Management R81.20 Administration Guide](https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_HarmonyEndpointWebManagement_AdminGuide/Default.htm)     |
> | [R81.20 Release Notes](https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RN/Default.htm)                                                                                  |
> | [Endpoint Security Server R81.10 Administration Guide](https://sc1.checkpoint.com/documents/R81.10/SmartEndpoint_OLH/EN/Default.htm)                                                            |
> | [Endpoint Security Web Management R81.10 Administration Guide](https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_HarmonyEndpointWebManagement_AdminGuide/Default.htm)     |
> | [R81.10 Release Notes](https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_RN/Topics-RN/Whats-New.htm)                                                                      |
>
> <br />
>
> For more information on Check Point releases, see: [Release map](https://support.checkpoint.com/results/sk/sk152052), [Upgrade and Backward Compatibility maps](https://support.checkpoint.com/results/sk/sk113113), [Releases plan](https://support.checkpoint.com/results/sk/sk95746).
> You can also visit our [Endpoint forum](https://community.checkpoint.com/community/infinity-general/endpoint), [Remote Access forum](https://community.checkpoint.com/community/infinity-general/remote-access), or any other [CHECKMATES forum](https://community.checkpoint.com/) to ask questions and get answers from technical peers and Support experts.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
