CVE-2025-0309: Netskope Client Local Elevation of Privileges
An insufficient validation on the server connection endpoint in Netskope Client allows local users to elevate privileges on the system. The insufficient validation allows Netskope Client to connect to any other server with Public Signed CA TLS certificates and send specially crafted responses to elevate privileges.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0309?
The severity of CVE-2025-0309 is considered to be high due to the potential for privilege escalation.
How do I fix CVE-2025-0309?
Fixing CVE-2025-0309 involves updating to the latest version of the Netskope Client that addresses the insufficient validation vulnerability.
Who is affected by CVE-2025-0309?
CVE-2025-0309 affects users of the Netskope Client software that is running in environments with improper server connection validation.
What type of vulnerability is CVE-2025-0309?
CVE-2025-0309 is classified as a privilege escalation vulnerability due to insufficient validation in server connections.
When was CVE-2025-0309 published?
CVE-2025-0309 was published in 2025, reflecting its status as a newly discovered vulnerability.