SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-6145

Forcepoint VPN Client for Windows versions lower than 6.6.1 have an unquoted search path vulnerability.

MEDIUM 6.7EPSS 0.66%

Does this matter?

Lower severity and a low EPSS score (0.66%). Track it; it rarely justifies an emergency change on its own.

Description

Forcepoint VPN Client for Windows versions lower than 6.6.1 have an unquoted search path vulnerability. This enables local privilege escalation to SYSTEM user. By default, only local administrators can write executables to the vulnerable directories. Forcepoint thanks Peleg Hadar of SafeBreach Labs for finding this vulnerability and for reporting it to us.

CVSS 3.1
6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
0.66% probability · 50th percentile
CISA KEV
Not listed
Weakness
CWE-428
Affected
forcepoint/vpn client
Source
psirt@forcepoint.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.