THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-34290 — Versa SASE Client for Windows versions released between 7.8.7 and 7.9.4 contain a local privilege escalation vulnerability in the audit log export functionality. The client communicates user-controlled file paths to a privileged service, which performs file system operations with

[NVD] CVE-2025-34290 — Versa SASE Client for Windows versions released between 7.8.7 and 7.9.4 contain a local privilege escalation vulnerability in the audit log export functionality. The client communicates user-controlled file paths to a privileged service, which performs file system operations with

lownvdPublished 2025-12-20

CVE-2025-34290 CVSS: None Published: 2025-12-20T20:15:50.553

Versa SASE Client for Windows versions released between 7.8.7 and 7.9.4 contain a local privilege escalation vulnerability in the audit log export functionality. The client communicates user-controlled file paths to a privileged service, which performs file system operations without impersonating the requesting user. Due to improper pr

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-34290