PT-2025-52564 · Versa Networks · Versa Sase Client For Windows

·

CVE-2025-34290

·

Published

2025-12-20

·

Updated

2025-12-21

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Versa SASE Client for Windows versions 7.8.7 through 7.9.4
Description The software contains a local privilege escalation issue in the audit log export functionality. The client sends user-controlled file paths to a privileged service, which then performs file system operations without using the requesting user's permissions. A time-of-check time-of-use race condition, combined with symbolic link and mount point manipulation, allows a local authenticated attacker to make the service delete arbitrary directories with SYSTEM privileges. This can lead to the deletion of protected system folders, such as C:Config.msi, and subsequent execution as NT AUTHORITYSYSTEM through MSI rollback techniques.
Recommendations Update Versa SASE Client for Windows versions prior to 7.9.5.

Fix

LPE

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-34290

Affected Products

Versa Sase Client For Windows