---
id: CVE-2025-15642
title: >-
  Netskope is notified about a potential gap in its Netskoped Client for Windows
  systems where a malicious insider with admin privileges can lead to bypassing
  the NSClient Tamper Protections due to weak Discretionary Access Control List
  (D…
summary: >-
  Netskope is notified about a potential gap in its Netskoped Client for Windows
  systems where a malicious insider with admin privileges can lead to bypassing
  the NSClient Tamper Protections due to weak Discretionary Access Control List
  (D…
severity: none
cwe:
  - CWE-276
published: '2026-06-17'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T21:10:00.190'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-15642'
references:
  - url: >-
      https://www.netskope.com/resources/netskope-resources/netskope-security-advisory-nskpsa-2025-008
    label: psirt@netskope.com
tags:
  - nvd
epss: 0.00143
epssPercentile: 0.03066
ingestedAt: '2026-09-30T21:25:07.752Z'
---

## Overview

Netskope is notified about a potential gap in its Netskoped Client for Windows systems where a malicious insider with admin privileges can lead to bypassing the NSClient Tamper Protections due to weak Discretionary Access Control List (DACLs) on the service object and related registry keys,.
  *  Product Name: Netskope Client
  *  Affected Platform: Windows
  *  Affected Version: All version below R138

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
