CVE-2019-6145

MEDIUM

Forcepoint VPN Client < 6.6.1 - Local Privilege Escalation via Unquoted Search Path

Title source: llm
STIX 2.1

Description

Forcepoint VPN Client for Windows versions lower than 6.6.1 have an unquoted search path vulnerability. This enables local privilege escalation to SYSTEM user. By default, only local administrators can write executables to the vulnerable directories. Forcepoint thanks Peleg Hadar of SafeBreach Labs for finding this vulnerability and for reporting it to us.

References (2)

Core 2

Scores

CVSS v3 6.7
EPSS 0.0066
EPSS Percentile 46.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-428
Status published
Products (1)
forcepoint/vpn_client < 6.6.1
Published Sep 20, 2019
Tracked Since Feb 18, 2026