> Source: [sk183512](https://support.checkpoint.com/results/sk/sk183512)

# sk183512 - Threat Extraction Software Blade may inadvertently delete some system files

| Property | Value |
|----------|-------|
| Solution ID | sk183512 |
| Date Created | 2025-05-29 |
| Last Modified | 2025-09-14 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * In a rare case, during the automatic deletion of temporary files the Threat Extraction Software Blade may inadvertently delete some Gaia OS system files, which may render the Security Gateway unstable.

* This issue applies to all these Security Gateways, Clusters, Scalable Platform Security Group and VSX Virtual Systems:

  * The Threat Extraction Software Blade is enabled, and the IPS Software Blade is disabled
  * Versions R80.30 and higher
  * All Quantum Security Gateways on all hardware platforms (including Check Point Threat Emulation appliances)
  * All CloudGuard Network Security Gateways
* This issue does not apply to Quantum Spark Gateways (neither Locally Managed, nor Centrally Managed).

## Solution

This problem was fixed. The fix is included in:

* [Jumbo Hotfix Accumulator for Quantum Force 3900 Appliances](https://support.checkpoint.com/results/sk/sk183557) starting from Take 22
* [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 25
* [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 103
* [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 177

If you choose not to upgrade, there are two possible options.

* **Option 1 (Recommended)** - Install a Hotfix on the Security Gateway / each Cluster Member / Scalable Platform Security Group:

  Note - Install this hotfix, if in your environment it is not possible to enable the IPS Software Blade or it is not possible to use one of the default Threat Prevention profiles.  
  Show / Hide this section  
  > Hotfixes:
  > >
  > > |------------|--------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------|
  > > | Version    | Hotfix                                                                                                                   | Prerequisite                                                                                                   |
  > > | **R82**    | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/138039) (TAR) | [R82 Jumbo Hotfix Accumulator](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm), Take 12        |
  > > | **R81.20** | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/138040) (TAR) | [R81.20 Jumbo Hotfix Accumulator](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm), Take 99  |
  > > | **R81.10** | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/138041) (TAR) | [R81.10 Jumbo Hotfix Accumulator](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm), Take 174 |
  > > | **R81**    | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/138042) (TAR) | [R81 Jumbo Hotfix Accumulator](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm), Take 107       |
  >
  > Notes:
  > * For hotfix installation instructions, refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).
  >
  > * If at this time you cannot install the required Jumbo Hotfix Accumulator Take (listed in the column "Prerequisite") on your Security Gateway / Cluster, then [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get this hotfix for your specific environment.
  >
  >   A Support Engineer will make sure the Hotfix is compatible with your environment before providing it. For faster resolution and verification, collect the [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Security Gateway / each Cluster Member involved in the case.
  > * Customers with the versions R80.30, R80.30SP, and R80.40 need to upgrade to one of the [supported versions](http://www.checkpoint.com/support-services/support-life-cycle-policy/) and install the provided hotfix.

* **Option 2** - Enable the IPS Software Blade and use one of the default Threat Prevention profiles.

  Note - If in your environment it is not possible to enable the IPS Software Blade or it is not possible to use one of the default Threat Prevention profiles, then follow "Option 1" above.  
  Show / Hide this section  
  1. Make sure the **IPS** Software Blade is enabled:

     1. On the left panel, click **Gateways \& Servers**.

     2. Double-click the Security Gateway / Cluster object.

     3. On the **General Properties** page, click the **Threat Prevention** tab.

     4. If in the left section, you selected **Custom Threat Prevention**:

        1. In the right section select the **IPS** Software Blade.

        2. In the **IPS First Time Activation** window, select **According to the Threat Prevention policy** and click **OK**.

     5. Click **OK** to close the Security Gateway / Cluster object.

  2. Make sure the Custom Threat Prevention policy for this Security Gateway / Cluster uses one of the **default** Threat Prevention profiles:

     Note - Follow this step if in the Security Gateway / Cluster object \> on the **General Properties** page \> on the **Threat Prevention** tab \> in the left section, you selected **Custom Threat Prevention**. The Autonomous Threat Prevention policy uses the required IPS settings.
     1. On the left panel, click **Security Policies**.

     2. In the **Threat Prevention** section, click **Custom Policy**.

     3. Refer to the **Action** column in **each** rule.

        Make sure this column shows one of these **default** Threat Prevention profiles:
        * **Basic**

        * **Optimized** (recommended)

        * **Strict**

        To select one of the default Threat Prevention profiles in a rule:
        1. Right-click the **Action** column in the rule.

        2. Select one of the default Threat Prevention profiles.

  3. Install the Threat Prevention policy.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
