Junglewise Threat Intelligence

CVE-2025-12694: Forcepoint VPN Client local privilege escalation to SYSTEM

CVE-2025-12694 · Severity: info · CVSS 8.5 · Published 2026-06-04

Executive brief

A security vulnerability in the Forcepoint VPN Client for Windows could allow a standard user to gain full administrative control over their computer. This software is typically used by employees to securely connect to corporate networks. If exploited, an attacker who already has limited access to a machine could bypass security restrictions to access sensitive data or install unauthorized software.

Technical details

A local privilege escalation vulnerability exists in the Forcepoint VPN Client for Windows due to the application executing processes with unnecessary privileges (CWE-250). A local, authenticated user with low privileges can exploit this flaw to escalate their permissions to the SYSTEM level. The vulnerability affects version 6.11.3 and all prior versions. Attackers must have local access to the target machine to execute the exploit, but no user interaction is required. Forcepoint has assigned a CVSS 4.0 score of 8.5 to this issue.

Affected products

  • Forcepoint VPN Client for Windows 6.11.3 and prior

Timeline

  • 2026-06-04: advisory: Initial advisory published by Forcepoint and NVD

References