CVE-2026-10739: Local privilege escalation in Cato Networks SDP Client for Windows chains a protobuf SID path traversal, a privileged SYSTEM delete, and a symlink redirect into a full SYSTEM shell. Patch threshold is any version below 6.12.6.
Key findings:
- The attack surface is the split-tunnel file upload feature. The low-privileged GUI sends a SplitTunnelUpload command over the named pipe \\.\pipe\cato-VPN to winvpnclient.cli.exe running as NT AUTHORITY\SYSTEM. The UserSidString field in the UiRegister protobuf message is attacker-controlled and is used verbatim to build the output path ccst_<SID>.stp under ProgramData\CatoNetworks\SDPClient\ST. Because ..\ sequences are not stripped, a crafted SID like \\..\\..\\..\\tmp\\foobar redirects the write or delete outside the split-tunnel directory entirely.
- The named pipe enforces a certificate check: the service calls GetNamedPipeClientProcessId, resolves the client image with QueryFullProcessImageNameW, and verifies the Cato signing certificate via memcmp against expected certificate material. A random process is rejected. The bypass is manual DLL mapping into a legitimately signed CatoClient.exe process, so the IPC gate sees a valid Cato-signed origin and passes the check without any file modification.
- The weaponized primitive is the cleanup delete path, not the write. When a readable but invalid .ccst file is uploaded, winvpnclient.cli.exe deletes the generated .stp artifact as SYSTEM. Combined with the path traversal, the attacker controls exactly what SYSTEM deletes. A junction and an RPC Control object directory symlink redirect that delete to C:\Config.Msi, invoking the well-documented Windows Installer MSI rollback escalation chain and landing a SYSTEM shell. Procmon confirms the delete hitting Config.Msi before the MSI stage executes.
- Affected versions are confirmed on 6.2.0 and 6.4.6; the vendor states all versions before 6.12.6 are vulnerable. CVE-2026-10739 was assigned 2026-09-30. The vendor published a security announcement to customers the same day. Quarkslab's coordinated disclosure ran from 2026-06-02 to today's publication.
Responder takeaway: On any Windows endpoint running Cato Client, look for winvpnclient.cli.exe performing file deletes outside ProgramData\CatoNetworks\SDPClient\ST, especially touching C:\Config.Msi or junction points under C:\poc or similar attacker-created directories. Hunt for CatoClient.exe spawning unexpected child processes or hosting injected threads, particularly ones opening \\.\pipe\cato-VPN from an unusual call stack. The path traversal payload would appear in pipe traffic as a UiRegister message (command ID 34, body field 25) with a UserSidString containing backslash sequences rather than a valid SID format. Prioritize upgrading to 6.12.6 across your endpoint inventory, but first check whether any endpoint has already seen a Config.Msi deletion event paired with Cato process activity. The PoC payload source CatoPipePayload.c is referenced in the Quarkslab report.
#DFIR_Radar