Executive brief
The Netskope Client for Windows, which provides secure network access and data protection, contains a security gap in its self-protection mechanisms. A malicious user who already has administrative access to a computer can bypass the software's tamper protections. This could allow an attacker to disable security monitoring or modify the client's configuration to evade corporate policies.
Technical details
A vulnerability exists in the Netskope Client for Windows due to incorrect default permissions (CWE-276) on the service object and associated registry keys. Specifically, weak Discretionary Access Control Lists (DACLs) allow a local attacker with administrative privileges to modify or disable the service, effectively bypassing the NSClient Tamper Protections. This issue affects all versions prior to R138. Users are advised to update to version R138 or later to ensure proper access controls are enforced on these sensitive system components.
Affected products
- Netskope Netskope Client All versions below R138
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory