PT-2025-52564 · Versa Networks · Versa Sase Client For Windows

Eduardo Pérez Malumbres Cervera

·

Published

2025-12-20

·

Updated

2025-12-21

·

CVE-2025-34290

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Versa SASE Client for Windows versions 7.8.7 through 7.9.4
Description The software contains a local privilege escalation issue in the audit log export functionality. The client sends user-controlled file paths to a privileged service, which then performs file system operations without using the requesting user's permissions. A time-of-check time-of-use race condition, combined with symbolic link and mount point manipulation, allows a local authenticated attacker to make the service delete arbitrary directories with SYSTEM privileges. This can lead to the deletion of protected system folders, such as C:Config.msi, and subsequent execution as NT AUTHORITYSYSTEM through MSI rollback techniques.
Recommendations Update Versa SASE Client for Windows versions prior to 7.9.5.

Fix

LPE

Time Of Check To Time Of Use

Weakness Enumeration

Related Identifiers

CVE-2025-34290

Affected Products

Versa Sase Client For Windows