Impact
The vulnerability is a local privilege escalation flaw in the WatchGuard Mobile VPN with SSL client for Windows. It allows a local attacker to gain NT AUTHORITY\\SYSTEM privileges on the machine where the client runs. This elevation can let the attacker execute arbitrary code, modify system settings, and otherwise fully control the host. The weakness is CWE‑732: Incorrect Permissions Assignment, indicating that the flaw involves incorrect assignment of file or resource permissions.
Affected Systems
The flaw affects the Mobile VPN with SSL client for Windows up to and including version 2026.2. The product is part of the WatchGuard Fireware OS suite. A Windows system that has the vulnerable client installed is at risk. The vulnerability is local in nature, meaning the attacker must have local access to the machine to trigger it. Because the client runs under a local user account, a local threat actor can exercise the flaw without network connectivity.
Risk and Exploitability
The CVSS base score of 7.3 indicates a high severity vulnerability, but the EPSS score of less than 1% indicates a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV local; an attacker must have access to the client’s installation directory or be able to execute code in that environment. Once exploited, the attacker can immediately attain full SYSTEM privileges on the host, enabling arbitrary code execution, persistence, and lateral movement. Because the flaw can be triggered with local privileges, the risk is moderate to high in environments where the client is widely deployed and local accounts have significant permissions.
OpenCVE Enrichment