CVE-2024-24916: DLL-HiJacking
Published Jun 19, 2025
·Updated
Untrusted DLLs in the installer's directory may be loaded and executed, leading to potentially arbitrary code execution with the installer's privileges (admin).
Affected Software
27 affected components
All of the following
Any of the following
Checkpoint Smartconsole=r81.10-build400
Checkpoint Smartconsole=r81.10-build402
Checkpoint Smartconsole=r81.10-build404
Checkpoint Smartconsole=r81.10-build406
Checkpoint Smartconsole=r81.10-build407
Checkpoint Smartconsole=r81.10-build409
Checkpoint Smartconsole=r81.10-build410
Checkpoint Smartconsole=r81.10-build412
Checkpoint Smartconsole=r81.10-build413
Checkpoint Smartconsole=r81.10-build414
Checkpoint Smartconsole=r81.10-build416
Checkpoint Smartconsole=r81.10-build417
Checkpoint Smartconsole=r81.10-build418
Checkpoint Smartconsole=r81.10-build420
Checkpoint Smartconsole=r81.10-build423
Checkpoint Smartconsole=r81.10-build424
Checkpoint Smartconsole=r81.10-build425
Checkpoint Smartconsole=r81.20-build640
Checkpoint Smartconsole=r81.20-build641
Checkpoint Smartconsole=r81.20-build645
Checkpoint Smartconsole=r81.20-build646
Checkpoint Smartconsole=r81.20-build649
Checkpoint Smartconsole=r81.20-build651
Checkpoint Smartconsole=r81.20-build653
Checkpoint Smartconsole=r81.20-build654
Checkpoint Smartconsole=r81.20-build655
Microsoft Windows
Event History
Jun 19, 2025
CVE Published
via MITRE·01:17 PM
Data Sourced
via MITRE·01:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Jan 2, 57623
Event
via NVD·11:46 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-24916?
CVE-2024-24916 has a high severity rating due to the potential for arbitrary code execution with elevated privileges.
2
How do I fix CVE-2024-24916?
To fix CVE-2024-24916, ensure you update to the latest version of Checkpoint Smartconsole that includes security patches.
3
What software is affected by CVE-2024-24916?
CVE-2024-24916 affects multiple builds of Checkpoint Smartconsole version r81.10 and r81.20.
4
What type of vulnerability is CVE-2024-24916?
CVE-2024-24916 is an untrusted DLL vulnerability that allows malicious code execution.
5
Can CVE-2024-24916 be exploited remotely?
CVE-2024-24916 requires local access to the installer’s directory to exploit, but it may lead to significant security risks.