The WatchGuard Mobile VPN with SSL Client on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY/SYSTEM on the Windows machine where the VPN Client is installed.This issue affects the Mobile VPN with SSL Client 12.0 up to and including 12.11.2.
History

Fri, 05 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 04 Dec 2025 22:00:00 +0000

Type Values Removed Values Added
Description The WatchGuard Mobile VPN with SSL Client on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY/SYSTEM on the Windows machine where the VPN Client is installed.This issue affects the Mobile VPN with SSL Client 12.0 up to and including 12.11.2.
Title WatchGuard Mobile VPN with SSL Local Privilege Escalation via Update Package
First Time appeared Watchguard
Watchguard mobile Vpn With Ssl Client
Weaknesses CWE-77
CPEs cpe:2.3:a:watchguard:mobile_vpn_with_ssl_client:*:*:*:*:*:*:*:12.0
Vendors & Products Watchguard
Watchguard mobile Vpn With Ssl Client
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published: 2025-12-04T21:56:51.105Z

Updated: 2025-12-06T04:55:45.388Z

Reserved: 2025-03-03T21:03:19.589Z

Link: CVE-2025-1910

cve-icon Vulnrichment

Updated: 2025-12-05T15:37:48.437Z

cve-icon NVD

Status : Received

Published: 2025-12-04T22:15:48.583

Modified: 2025-12-04T22:15:48.583

Link: CVE-2025-1910

cve-icon Redhat

No data.