CVE-2025-0309Disclosure

LOWCVSS 6.0 · MEDIUM

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

An insufficient validation on the server connection endpoint in Netskope Client allows local users to elevate privileges on the system. The insufficient validation allows Netskope Client to connect to any other server with Public Signed CA TLS certificates and send specially crafted responses to elevate privileges.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-24: 2PoC Mentioned / Linked · 2026-03-24: 1Patch / Workaround · 2026-03-24: 1Technical Details · 2026-03-24: 103-24
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Rich Warren@buffaloverflow
    Patch

    here's my writeup for the latest Netskope LPE this was a fun bypass of CVE-2025-0309, and highlights an interesting cloud-based attack surface :) https://blog.amberwolf.com/blog/2026/march/patch-bypass---netskope-client-for-windows---local-privilege-escalation-via-rogue-server/

    Post summary

    The post outlines a patch bypass for CVE‑2025‑0309 in Netskope, addressing the vulnerability with a workaround and highlighting a cloud-based attack surface, but lacks specific exploitation details.

    2300692311.6K
    10.6K followersView on X
  • AmberWolf@AmberWolfSec
    Disclosure

    In August 2025 we disclosed CVE-2025-0309: a local privilege escalation in the Netskope Windows client via rogue server enrolment. (You can read more at https://blog.amberwolf.com/blog/2025/august/advisory---netskope-client-for-windows---local-privilege-escalation-via-rogue-server/) (2/6)

    Post summary

    The post announces the disclosure of CVE-2025-0309, a local privilege escalation vulnerability in the Netskope Windows client caused by rogue server enrollment.

    11011308
    433 followersView on X

Explore more