Impact
A local privilege escalation flaw in the Forcepoint VPN Client for Windows allows any non-administrative user to gain SYSTEM privileges. The vulnerability is classified as CWE-250, indicating a privilege escalation flaw. If exploited, the attacker can run arbitrary code with full system rights, compromising confidentiality, integrity, and availability of the host. The description provides no additional details about the trigger or code path.
Affected Systems
Affected systems are Forcepoint VPN Client for Windows versions 6.11.3 and earlier, as noted in the vendor advisory. Users running any of these releases are vulnerable when the unpatched client is installed and operated by a local account.
Risk and Exploitability
The CVSS score of 8.5 classifies this issue as high severity. The likely attack vector is local access by a non-administrative user, inferred from the description that the vulnerability affects local users. Exploitation requires local access, so only logged-in users can trigger the behavior. EPSS score < 1% and the absence from CISA’s KEV catalog suggest a relatively lower likelihood of widespread, automated attacks. Attackers would need to run the affected client or supply a crafted input to the local user to elevate privileges, after which they would obtain unrestricted system control.
OpenCVE Enrichment