- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi Guys,
Do you know if Checkpoints are affected by Meltdown and Spectre and if so, what is the timeframe for a patch being released?
Regards,
Octavian
Hi Octavian,
Regards,
Ronen
Thank you Ronen. I've just seen this. It seems that someone else has posted before me.
Kind regards,
Octavian
Hi,
Our SE suggested I ask this here so apologies in advance if not the right place 🙂
I'm thinking of what can CP do to protect user networks as opposed to the gateways themselves - to whick access should be tightly restricted.
Specifically, I was thinking of the scenario where a user on the network downloads a malicious piece of code that exploits this vulnerability. Patching 500-odd PCs is a time-consuming process for a business when those devices are in active use. What plans – if any – do CP have to trap such malicious code via TEM and CPU-level emulation? That would be a strong selling point.
Thanks,
Dave
Dave,
this is exactly what Check Point IPS is about. Here is the protection you are looking for.
Danny
Hello, What about code execution during traffic inspection?
The only potential "arbitrary" code that might be executed as part of Threat Prevention is during Threat Emulation.
This happens on Threat Emulation specific appliances in VMs.
A feature that would be needed during the exploit phase is disabled on Check Point appliances, as noted in the SK linked above.
Hi Dameon,
I think the sk article does a good job of clarifying that CP itself is not vulnerable; the questions are really about what a CP deployment can do to protect what is behind it.
Danny (above) linked to an IPS protection that appears to address part of this (via javascript), but not via arbitrary code. For clarification of your reply above, are you stating that TEM can already detect this or will be able to detect this for clients behind the gateway downloading a malicious executable? The difference between 'can' and 'will be able to' is quite a big one!
Thanks.
Right, IPS only gets the Javascript exploit vector.
As for Threat Emulation's role in all this, stay tuned ![]()
Hi PhoneBoy,
Can you clarify about what feature exactly has been turned off?
I have a customer asking about how exactly are we mitigating these threats on our gateways...(he already read the sk involved)
Check SK 122205
See also the note from our Research blog on the topic: Detection of the Meltdown and Spectre Vulnerabilities Using CheckPoint CPU-Level Technology - Check ...
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Wed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY