CVE-2025-15642 Details
Description
Netskope is notified about a potential gap in its Netskoped Client for Windows systems where a malicious insider with admin privileges can lead to bypassing the NSClient Tamper Protections due to weak Discretionary Access Control List (DACLs) on the service object and related registry keys,. * Product Name: Netskope Client * Affected Platform: Windows * Affected Version: All version below R138
A vulnerability exists in the Netskope Client for Windows, all versions prior to R138, where a malicious insider with administrative privileges could bypass the NSClient Tamper Protections. This issue arises from weak Discretionary Access Control Lists (DACLs) on the service object and related registry keys, combined with a lack of kernel-enforced self-protection in the Netskope Client.
Netskope has released a security patch for this vulnerability in version R138 and above. Instructions for downloading the updated client are available on the Netskope Support website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.netskope.com/resources/netskope-resources/netskope-security-advisory-nskpsa-2025-008 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-276 | Incorrect Default Permissions | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | New CVE Received | [email protected] |