Executive brief
WatchGuard Mobile VPN with SSL is a client software that allows Windows users to securely connect to corporate networks remotely. A locally authenticated non-administrative user can exploit a flaw in the update mechanism to gain full system-level (SYSTEM) privileges on the Windows machine, potentially allowing them to install malware, access sensitive data, or modify system settings without restriction.
Technical details
The vulnerability is a command injection flaw (CWE-77) in the update package handling mechanism of the WatchGuard Mobile VPN with SSL Client on Windows. A locally authenticated non-administrative user can exploit improper neutralization of special elements in a command to escalate privileges to NT AUTHORITY/SYSTEM. The attack requires local access to the affected machine where the VPN client is installed. The flaw has been fixed in version 12.11.3 and later. No exploitation in the wild has been reported by WatchGuard.
Affected products
- WatchGuard Mobile VPN with SSL Client 11.0 to before 12.11.3
Timeline
- 2025-12-04: disclosed
- 2025-12-04: patched: Version 12.11.3 and later