Junglewise Threat Intelligence

CVE-2025-15641: Netskope Client anti-tampering bypass via insufficient IOCTL access control

CVE-2025-15641 · Severity: info · CVSS 6.8 · Published 2026-06-17

Executive brief

A security vulnerability in the Netskope Client for Windows could allow a user with administrative access to bypass the software's built-in anti-tampering protections. By sending specially crafted requests to the system driver, a malicious insider could disable or interfere with the security client's operations. This could lead to a loss of security monitoring or enforcement on the affected workstation.

Technical details

A vulnerability classified as CWE-782 (Exposed IOCTL with Insufficient Access Control) exists in the Netskope Client for Windows. The flaw allows a local attacker with administrative privileges to send crafted Input/Output Control (IOCTL) requests to the kernel-mode driver. Successful exploitation enables the attacker to bypass all anti-tampering protections implemented by the NSClient. This issue is addressed in Netskope Client version R138 and later.

Affected products

  • Netskope Netskope Client All versions below R138

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References