CVE-2025-34290 Details
Description
Versa SASE Client for Windows versions released between 7.8.7 and 7.9.4 contain a local privilege escalation vulnerability in the audit log export functionality. The client communicates user-controlled file paths to a privileged service, which performs file system operations without impersonating the requesting user. Due to improper privilege handling and a time-of-check time-of-use race condition combined with symbolic link and mount point manipulation, a local authenticated attacker can coerce the service into deleting arbitrary directories with SYSTEM privileges. This can be exploited to delete protected system folders such as C:\\Config.msi and subsequently achieve execution as NT AUTHORITY\\SYSTEM via MSI rollback techniques.
A local privilege escalation vulnerability has been identified in the Versa SASE Client for Windows, specifically in versions 7.8.7 prior to 7.9.4. This vulnerability arises in the audit log export feature, where user-controlled file paths are sent to a privileged service that performs file system operations without proper user impersonation. This flaw, combined with a time-of-check time-of-use race condition and manipulation of symbolic links and mount points, allows a local authenticated attacker to trick the service into deleting arbitrary directories with SYSTEM privileges. Exploitation of this vulnerability could involve removing protected system folders, such as C:\Config.msi, and subsequently executing code as NT AUTHORITY\SYSTEM using MSI rollback techniques.
Users can update to Versa SASE Client for Windows version 7.9.5 or later, where this vulnerability has been addressed. For versions prior to 7.9.5, the audit log export functionality now operates strictly within the user context, preventing any actions from being executed with elevated privileges. Enhanced validation has also been implemented to ensure only valid file formats are processed, blocking I/O operations on unexpected or malicious file types.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-250 | Execution with Unnecessary Privileges | [email protected] |
| CWE-367 | Time-of-check Time-of-use (TOCTOU) Race Condition | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| versa-networks sase client | >= 7.8.7, < 7.9.5 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 25, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 20, 2025 | New CVE Received | [email protected] |