Home

Description

Execution with unnecessary privileges in Forcepoint NGFW Engine allows local privilege escalation.This issue affects NGFW Engine through 6.10.19, through 7.3.0, through 7.2.4, through 7.1.10.

PUBLISHED Reserved 2025-11-04 | Published 2026-03-11 | Updated 2026-03-11 | Assigner forcepoint




HIGH: 7.3CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-250 Execution with unnecessary privileges

Product status

Default status
unaffected

Any version
affected

Any version
affected

Any version
affected

Any version
affected

Credits

Francesco Caserta, Andrea Lomuscio and Alessandro Ruggieri of the Italian National Cybersecurity Agency finder

References

support.forcepoint.com/...rivilege-Escalation-in-NGFW-Engine

cve.org (CVE-2025-12690)

nvd.nist.gov (CVE-2025-12690)

Download JSON