PT-2025-33117 · Netskope · Netskope Client

Richard Warren

·

Published

2025-08-14

·

Updated

2025-08-31

·

CVE-2025-0309

CVSS v4.0
6.0
VectorAV:P/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:H/SI:H/SA:H

**Name of the Vulnerable Software and Affected Versions:**

Netskope Client for Windows (affected versions not specified)

**Description:**

An insufficient validation exists on the server connection endpoint in Netskope Client, allowing local users to elevate privileges on the system. This insufficient validation enables the client to connect to any server presenting publicly signed CA TLS certificates and transmit specifically crafted responses to escalate privileges.

**Recommendations:**

At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2025-0309

Affected Products

Netskope Client