Description
Netskope is notified about a potential gap in its Netskoped Client for Windows systems where a malicious insider with admin privileges can lead to bypassing the NSClient Tamper Protections due to weak Discretionary Access Control List (DACLs) on the service object and related registry keys,. * Product Name: Netskope Client * Affected Platform: Windows * Affected Version: All version below R138
Problem types
CWE-276 Incorrect default permissions
Product status
Any version before 138
Credits
Netskope credits Juan Pablo Barriga for reporting this flaw.
References
www.netskope.com/...tskope-security-advisory-nskpsa-2025-008