An insufficient validation on the server connection endpoint in Netskope Client allows local users to elevate privileges on the system. The insufficient validation allows Netskope Client to connect to any other server with Public Signed CA TLS certificates and send specially crafted responses to elevate privileges.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-24661 An insufficient validation on the server connection endpoint in Netskope Client allows local users to elevate privileges on the system. The insufficient validation allows Netskope Client to connect to any other server with Public Signed CA TLS certificates and send specially crafted responses to elevate privileges.
Fixes

Solution

Update the Netskope Client to version 129.0.0 or newer


Workaround

There are multiple configurations which can mitigate and reduce potential exposure: * Block connection/access to any new domain or URLs to NS Client apart from goskope.com * Use EDR tools to monitor connections from NS Client to any random domains and block it * Monitor for addition of any self signed certificates in operating system certificate store * Monitor the status of NS Client

History

Fri, 15 Aug 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 15 Aug 2025 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-295

Fri, 15 Aug 2025 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Netskope
Netskope netskope
Vendors & Products Netskope
Netskope netskope

Thu, 14 Aug 2025 04:45:00 +0000

Type Values Removed Values Added
Description An insufficient validation on the server connection endpoint in Netskope Client allows local users to elevate privileges on the system. The insufficient validation allows Netskope Client to connect to any other server with Public Signed CA TLS certificates and send specially crafted responses to elevate privileges.
Title Netskope Client Local Elevation of Privileges
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Netskope

Published:

Updated: 2025-08-15T12:58:27.857Z

Reserved: 2025-01-07T14:23:56.898Z

Link: CVE-2025-0309

cve-icon Vulnrichment

Updated: 2025-08-15T12:26:54.612Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-14T05:15:26.690

Modified: 2025-08-15T13:15:30.470

Link: CVE-2025-0309

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-08-14T12:59:53Z