CVE-2025-15642: Netskope Client Service Insufficient Access Controls
Netskope is notified about a potential gap in its Netskoped Client for Windows systems where a malicious insider with admin privileges can lead to bypassing the NSClient Tamper Protections due to weak Discretionary Access Control List (DACLs) on the service object and related registry keys,.
* Product Name: Netskope Client
* Affected Platform: Windows
* Affected Version: All version below R138
Security readout for executives and security teams
Plain-English summary
This issue affects Netskope Client on Windows before R138. A malicious insider who already has local administrator privileges may be able to weaken or bypass client tamper protections. The main business risk is loss of endpoint policy enforcement on compromised or misused administrator-controlled Windows systems.
Executive priority
Treat as a moderate-priority endpoint control issue. It is not described as remotely exploitable, but it can undermine Netskope protections where administrator access is misused or compromised.
Technical view
The vulnerability is an insufficient access control issue involving weak DACLs on the Netskope Client service object and related registry keys. The CVSS 4.0 vector is local, low complexity, high privileges, no user interaction, with high integrity and availability impact to the vulnerable system.
Likely exposure
Exposure is limited to Windows systems running Netskope Client versions below R138, especially where users, helpdesk staff, or attackers can obtain local administrator rights.
Exploitation context
The provided sources describe a malicious insider with administrator privileges. They do not report active exploitation, public exploit availability, or remote exploitation. CISA KEV status is false in the bundle.
Researcher notes
Evidence is narrow but consistent: CWE-276, Windows-only, high-privilege local attack precondition, and affected versions below R138. The bundle does not name specific registry paths, exploit artifacts, or detailed vendor fix mechanics.
Mitigation direction
Upgrade affected Windows clients to R138 or later where available.
Review Netskope advisory NSKPSA-2025-008 for vendor remediation details.
Reduce and monitor local administrator access on Windows endpoints.
Monitor for unauthorized changes to Netskope Client tamper protection state.
Use endpoint management controls to enforce client version compliance.
Validation and detection
Inventory Windows endpoints running Netskope Client.
Identify any Netskope Client versions below R138.
Confirm R138 or later deployment through endpoint management telemetry.
Review local administrator group membership on affected endpoints.
Check security logs for unexpected client service or registry permission changes.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-276: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
1ADP providers
2Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: total
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-276 · source CWE mapping
Incorrect Default Permissions
Incorrect Default Permissions represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.