{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2025-12694", "assignerOrgId": "e23ea22c-8c39-4eff-8980-2881e5ae54e2", "state": "PUBLISHED", "assignerShortName": "forcepoint", "dateReserved": "2025-11-04T12:33:50.696Z", "datePublished": "2026-06-04T12:04:33.952Z", "dateUpdated": "2026-06-04T13:21:13.818Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "e23ea22c-8c39-4eff-8980-2881e5ae54e2", "shortName": "forcepoint", "dateUpdated": "2026-06-04T12:04:33.952Z" }, "title": "Local Privilege Escalation in VPN Client", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-250", "description": "CWE-250 Execution with unnecessary privileges", "type": "CWE" } ] } ], "impacts": [ { "capecId": "CAPEC-233", "descriptions": [ { "lang": "en", "value": "CAPEC-233 Privilege Escalation" } ] } ], "affected": [ { "vendor": "Forcepoint", "product": "VPN Client", "platforms": [ "Windows" ], "versions": [ { "status": "affected", "version": "0", "lessThanOrEqual": "6.11.3", "versionType": "semver" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-administrative user to escalate privileges to SYSTEM. This issue affects VPN Client for Windows: versions 6.11.3 and prior.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "
A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-administrative user to escalate privileges to SYSTEM. This issue affects VPN Client for Windows: versions 6.11.3 and prior.