An insufficient validation on the server connection endpoint in Netskope Client allows local users to elevate privileges on the system. The insufficient validation allows Netskope Client to connect to any other server with Public Signed CA TLS certificates and send specially crafted responses to elevate privileges.
History

Fri, 15 Aug 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 15 Aug 2025 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-295

Fri, 15 Aug 2025 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Netskope
Netskope netskope
Vendors & Products Netskope
Netskope netskope

Thu, 14 Aug 2025 04:45:00 +0000

Type Values Removed Values Added
Description An insufficient validation on the server connection endpoint in Netskope Client allows local users to elevate privileges on the system. The insufficient validation allows Netskope Client to connect to any other server with Public Signed CA TLS certificates and send specially crafted responses to elevate privileges.
Title Netskope Client Local Elevation of Privileges
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Netskope

Published: 2025-08-14T04:35:15.287Z

Updated: 2025-08-15T12:58:27.857Z

Reserved: 2025-01-07T14:23:56.898Z

Link: CVE-2025-0309

cve-icon Vulnrichment

Updated: 2025-08-15T12:26:54.612Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-14T05:15:26.690

Modified: 2025-08-15T13:15:30.470

Link: CVE-2025-0309

cve-icon Redhat

No data.