CVE-2025-8305
Information Disclosure in Identity Agent Debug Files via Local Authenticated User
Publication date: 2025-12-22
Last updated on: 2025-12-22
Assigner: Check Point Software Technologies Ltd.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| checkpoint | identity_agent_for_terminal_services | 3.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability allows an authenticated local user to access sensitive information that is printed in plaintext within debug files of the Identity Agent for Terminal Services. This information can be used to claim security policy rules of another user.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized access to security policy rules of other users, potentially compromising security configurations and exposing sensitive information, which may result in privilege escalation or unauthorized actions within the system.