PT-2026-103124 · Cato Networks · Sdp Client For Windows
CVE-2026-10739
·
Published
2026-09-30
·
Updated
2026-10-01
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Cato Networks SDP Client for Windows versions prior to 6.12.6
Description
A local privilege escalation issue exists due to improper validation of a client-supplied Security Identifier (SID) over a local Inter-Process Communication (IPC) named pipe. A low-privileged user can send a
SplitTunnelUpload command via the .pipecato-VPN endpoint to the winvpnclient.cli.exe process, which runs with SYSTEM privileges. By providing a crafted UserSidString variable within the UiRegister protobuf message containing path traversal sequences (e.g., ..), an attacker can redirect file operations outside the intended directory. This allows the deletion of arbitrary files with SYSTEM privileges. This primitive can be combined with symlink redirects to target directories like C:Config.Msi to achieve a full SYSTEM shell.Recommendations
Update Cato Networks SDP Client for Windows to version 6.12.6.
Fix
LPE
Link Following
Relative Path Traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sdp Client For Windows