Netskope Client Privilege Escalation Vulnerability via Rogue Server

Vulnerability

A local privilege escalation vulnerability has been identified in the Netskope Client, affecting versions R128 and prior. The issue arises from insufficient validation of the server connection endpoint, allowing the client to connect to any server with Public Signed CA TLS certificates. Local users can exploit this flaw by sending specially crafted responses to elevate privileges on the system.

Impact

Exploitation of this vulnerability allows local users to escalate privileges to the SYSTEM level on the affected machine.

Remediation

Netskope has released a patch for this vulnerability in version R129. Customers are advised to upgrade to this version or higher. For download instructions, visit the Netskope Support page.

Added: Aug 14, 2025, 5:25 AM
Updated: Aug 14, 2025, 5:25 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.3
remediation
7.7
relevance
0.3
threat
4.8
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.