CVE-2025-12694: Local Privilege Escalation in VPN Client
Published Jun 4, 2026
·Updated
A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-administrative user to escalate privileges to SYSTEM. This issue affects VPN Client for Windows: versions 6.11.3 and prior.
Affected Software
2 affected components
Forcepoint VPN Client for Windows<=6.11.3
Forcepoint Vpn Client Windows<6.11.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Forcepoint VPN Client (Windows)to a version that resolves this vulnerability.Fixed in 6.12.0
Event History
Jun 4, 2026
CVE Published
via MITRE·12:04 PM
Data Sourced
via MITRE·12:04 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·12:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-12694?
The severity of CVE-2025-12694 is high, with a CVSS score of 8.5.
2
How do I fix CVE-2025-12694?
To fix CVE-2025-12694, upgrade the Forcepoint VPN Client to version 6.12.0 or later.
3
What type of vulnerability is CVE-2025-12694?
CVE-2025-12694 is a local privilege escalation vulnerability.
4
Which versions of the Forcepoint VPN Client are affected by CVE-2025-12694?
The affected versions of the Forcepoint VPN Client are 6.11.3 and prior.
5
What can attackers achieve by exploiting CVE-2025-12694?
Attackers can escalate privileges to SYSTEM level by exploiting CVE-2025-12694.