PT-2026-50186 · Netskope · Netskope Client
CVE-2025-15642
·
Published
2026-06-17
·
Updated
2026-06-17
CVSS v4.0
6.8
Medium
| Vector | AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Netskope Client versions prior to R138
Description
A gap exists in the Netskope Client for Windows systems where a malicious insider with administrative privileges can bypass NSClient Tamper Protections. This is caused by weak Discretionary Access Control Lists (DACLs), which are security settings that define which users or groups are granted access to specific objects, on the service object and related registry keys.
Recommendations
Update to version R138 or later.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netskope Client