CVE-2025-15642
Description
Netskope is notified about a potential gap in its Netskoped Client for Windows systems where a malicious insider with admin privileges can lead to bypassing the NSClient Tamper Protections due to weak Discretionary Access Control List (DACLs) on the service object and related registry keys,.
* Product Name: Netskope Client
* Affected Platform: Windows
* Affected Version: All version below R138
Summary dbcve.org
The Netskope Client for Windows contains weak Discretionary Access Control Lists (DACLs) on its service object and related registry keys. A malicious insider with administrator privileges can exploit these weak permissions to modify the NSClient service configuration or registry entries, effectively bypassing the built-in tamper protections designed to prevent modification of the security client.
Mitigation
Upgrade Netskope Client to version R138 or later to obtain the vendor patch that strengthens DACLs on the service object and registry keys. Alternatively, implement additional monitoring and access controls around the Netskope service and registry objects until the upgrade can be applied.