> Source: [sk184557](https://support.checkpoint.com/results/sk/sk184557)

# sk184557 - Check Point Response to CVE-2025-9142 - Harmony SASE Windows Client Vulnerability

| Property | Value |
|----------|-------|
| Solution ID | sk184557 |
| Date Created | 2026-01-13 |
| Last Modified | 2026-01-14 |
| Technical Level | General |

## Symptoms

- A local attacker can trigger Harmony SASE Windows client versions below 12.2 to write or delete files outside the intended certificate working directory. Exploitation can lead to overwriting system files (via symbolic links) and escalate privileges to system.

This issue received the ID [CVE-2025-9142](https://www.cve.org/CVERecord?id=CVE-2025-9142).

## Cause

The authentication and file-handling logic does not enforce strict trust boundaries. Under specific conditions, the system fails to validate data during certificate processing before using it in a privileged service component.

## Solution

* Upgrade Harmony SASE Windows Agent version 12.2 and above
* For more information about how to download the agent, see [sk182466 - Harmony SASE - Downloading the Agent](https://support.checkpoint.com/results/sk/sk182466).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
