CVE-2025-34290: Versa SASE Client for Windows < 7.9.5 Arbitrary Folder Deletion Leading to Local Privilege Escalation
Versa SASE Client for Windows versions released between 7.8.7 and 7.9.4 contain a local privilege escalation vulnerability in the audit log export functionality. The client communicates user-controlled file paths to a privileged service, which performs file system operations without impersonating the requesting user. Due to improper privilege handling and a time-of-check time-of-use race condition combined with symbolic link and mount point manipulation, a local authenticated attacker can coerce the service into deleting arbitrary directories with SYSTEM privileges. This can be exploited to delete protected system folders such as C:\\Config.msi and subsequently achieve execution as NT AUTHORITY\\SYSTEM via MSI rollback techniques.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34290?
CVE-2025-34290 is classified as a local privilege escalation vulnerability with a potential for significant impact.
How do I fix CVE-2025-34290?
To mitigate CVE-2025-34290, upgrade the Versa SASE Client for Windows to version 7.9.5 or later.
What versions of Versa SASE Client for Windows are affected by CVE-2025-34290?
CVE-2025-34290 affects Versa SASE Client for Windows versions between 7.8.7 and 7.9.4 inclusive.
What are the risks associated with exploiting CVE-2025-34290?
Exploiting CVE-2025-34290 allows an attacker to gain elevated privileges, potentially leading to unauthorized access and manipulation of sensitive data.
How can I identify if CVE-2025-34290 is present in my system?
You can identify CVE-2025-34290 by checking the version of your Versa SASE Client for Windows against the vulnerable versions listed.