Netskope was notified about a potential gap in its Netskope Client for Windows systems where a malicious insider with administrative privileges can potentially tamper with the customer IOCTL by sending crafted IOCTL requests to the driver. A successful exploit can result in the bypassing of all anti-tampering protections for the NSClient.Affected Product(s) and Version(s)
* Product Name: Netskope Client
* Affected Platform: Windows
* Affected Version: All version below R138
* Product Name: Netskope Client
* Affected Platform: Windows
* Affected Version: All version below R138
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Use any of the below version of Netskope Client: * R138 and above * R135 (135.1.19.2670 and above ) * R132 (132.0.27.2671 and above )
Workaround
No workaround available
References
History
Wed, 17 Jun 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Netskope was notified about a potential gap in its Netskope Client for Windows systems where a malicious insider with administrative privileges can potentially tamper with the customer IOCTL by sending crafted IOCTL requests to the driver. A successful exploit can result in the bypassing of all anti-tampering protections for the NSClient.Affected Product(s) and Version(s) * Product Name: Netskope Client * Affected Platform: Windows * Affected Version: All version below R138 | |
| Title | Netskope Client Exposed IOCTL with Insufficient Access Controls | |
| Weaknesses | CWE-782 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Netskope
Published:
Updated: 2026-06-17T01:50:01.108Z
Reserved: 2026-04-22T15:49:43.557Z
Link: CVE-2025-15641
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses