Disclosure summary
Versa SASE Client for Windows versions released between 7.8.7 and 7.9.4 contain a local privilege escalation vulnerability in the audit log export functionality. The client communicates user-controlled file paths to a privileged service, which performs file system operations without impersonating the requesting user. Due to improper privilege handling and a time-of-check time-of-use race condition combined with symbolic link and mount point manipulation, a local authenticated attacker can coerce the service into deleting arbitrary directories with SYSTEM privileges. This can be exploited to delete protected system folders such as C:\\Config.msi and subsequently achieve execution as NT AUTHORITY\\SYSTEM via MSI rollback techniques.
Source-reported weakness categories
CWE-250, CWE-367
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2025-34290
Open original source · Updated Oct 07, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| versa-networks | sase_client | * {"versionStartIncluding":"7.8.7","versionEndExcluding":"7.9.5"} |
Original records & references
- NIST NVD record
- CVE Program record
- security-portal.versa-networks.com — Vendor Advisory
- www.vulncheck.com — Third Party Advisory
PUBLISHED 2025-12-20T15:15:50-05:00
MODIFIED 2026-10-07T09:10:00-04:00
INGESTED 2026-10-08T12:40:10-04:00