Local Privilege Escalation Vulnerability in Forcepoint VPN Client for Windows
CVE-2025-12694

8.5HIGH

Key Information:

Vendor

Forcepoint

Vendor
CVE Published:
4 June 2026

What is CVE-2025-12694?

A vulnerability has been identified in the Forcepoint VPN Client for Windows, where a local non-administrative user can exploit this flaw to escalate their privileges to the SYSTEM level. This vulnerability affects versions up to 6.11.3, thereby potentially allowing attackers to gain unauthorized access and control over system resources. It is crucial for organizations using this software to apply updates and security patches to mitigate the risk associated with this vulnerability.

Affected Version(s)

VPN Client Windows 0 <= 6.11.3

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Francisco Jose Carot Ripolles (KPMG Spain)
.