Back to Labs
Security Advisory

CVE-2021-30356

About

A denial of service vulnerability was reported in Check Point Identity Agent before R81.018.0000, which could allow low privileged users to overwrite protected system files.

Weakness (CWE):CWE-59

Rainforest analyst review

Check Point Identity Agent, before R81.018.0000, lets a low-privileged user overwrite protected system files — a link-following (symlink) weakness where the agent writes to a path an unprivileged user can redirect, clobbering files they shouldn't be able to touch. It's reported as a denial-of-service issue, and the impact bears that out: integrity and availability are hit, confidentiality is not. This is about corrupting protected files on a machine, not stealing data from it.

The key precondition is that the attacker is already a low-privileged user on a host running the agent, so this is a local abuse of trust, not a remote break-in. The realistic outcome is a user overwriting protected system files to disrupt the endpoint — degrading or disabling functionality, or potentially tampering with files in a way that undermines the security agent itself. That local, already-authenticated requirement is what keeps it in the high-but-not-critical band despite the file-overwrite power; nobody reaches this without first being on the box.

Our angle is standard agent-fleet patch coverage weighted by where untrusted local users exist. We'd update Identity Agent to R81.018.0000 or later across managed endpoints, prioritizing shared or multi-user machines where a low-privileged user turning to file corruption is most plausible. Because a symlink flaw that lets a user tamper with a security agent's own files can undercut endpoint defenses, we rank it a notch above a plain DoS and fold it into normal endpoint-agent maintenance rather than emergency response.

References

Related CVEs

No related CVEs.

Frequently asked questions

What is CVE-2021-30356?

A denial of service vulnerability was reported in Check Point Identity Agent before R81.018.0000, which could allow low privileged users to overwrite protected system files.

How severe is CVE-2021-30356?

CVE-2021-30356 carries a CVSS 3.1 base score of 8.1, rated high. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 80 out of 100, in the high band.

How is CVE-2021-30356 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H): attack vector Network, attack complexity Low, privileges required Low, user interaction None. Impact on confidentiality None, integrity High and availability High.

Which products are affected by CVE-2021-30356?

Public advisories list the following as affected: identity agent. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2021-30356?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email