PT-2026-50186 · Netskope · Netskope Client

CVE-2025-15642

·

Published

2026-06-17

·

Updated

2026-06-17

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Netskope Client versions prior to R138
Description A gap exists in the Netskope Client for Windows systems where a malicious insider with administrative privileges can bypass NSClient Tamper Protections. This is caused by weak Discretionary Access Control Lists (DACLs), which are security settings that define which users or groups are granted access to specific objects, on the service object and related registry keys.
Recommendations Update to version R138 or later.

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-15642

Affected Products

Netskope Client