Executive brief
Versa SASE Client is a Secure Access Service Edge (SASE) software agent for Windows that manages network security and access policies. A vulnerability in its audit log export feature allows a local user on the same system to delete protected system folders and take complete control of the computer by exploiting improper privilege handling and race conditions. An attacker could use this to disable security controls or steal sensitive data by running malicious commands as the highest system privilege level.
Technical details
This local privilege escalation vulnerability exists in the audit log export functionality of Versa SASE Client versions 7.8.7 through 7.9.4. The vulnerable privileged service receives user-controlled file paths without impersonating the requesting user before performing file system operations. The flaw combines a time-of-check time-of-use (TOCTOU) race condition with symbolic link and mount point manipulation to allow a local authenticated attacker to coerce deletion of arbitrary directories with SYSTEM privileges. An attacker can exploit this to delete protected system folders like C:\Config.msi and subsequently achieve code execution as NT AUTHORITY\SYSTEM via MSI rollback techniques. The fix is available in version 7.9.5 and later.
Affected products
- Versa Networks SASE Client for Windows 7.8.7 through 7.9.4
Timeline
- 2025-12-20: disclosed
- 2025-12-20: patched: Fixed in version 7.9.5