# WatchGuard Mobile VPN SSL更新包本地提权漏洞
## 概述
WatchGuard Mobile VPN with SSL Client for Windows 存在权限提升漏洞,允许本地认证的普通用户提升权限至 NT AUTHORITY/SYSTEM。
## 影响版本
受影响版本为 12.0 至 12.11.2(含)。
## 细节
漏洞存在于安装了 Mobile VPN with SSL Client 的 Windows 系统中。攻击者可通过特定方式利用该漏洞,以非管理员身份获得系统最高权限。
## 影响
成功利用该漏洞的攻击者可在目标系统上以 SYSTEM 权限执行任意操作,包括安装程序、修改配置、访问敏感数据等。
是否为 Web 类漏洞: 未知
判断理由:
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | Proof-of-Concept for exploiting CVE-2025-1910, a local privilege escalation within Watchguard's Mobile VPN with SSL client. | https://github.com/lutrasecurity/CVE-2025-1910-WatchGuard-Privilege-Escalation | POC详情 |
标题: WatchGuard Mobile VPN with SSL Local Privilege Escalation | WatchGuard Technologies -- 🔗来源链接
标签:
神龙速读:
## 漏洞关键信息
**Advisory ID**: WSGA-2025-00008
**CVE**: CVE-2025-1910
**Impact**: High
**Status**: Resolved
**Product Family**: Other Software
**Published Date**: 2025-05-28
**Updated Date**: 2025-12-04
**Workaround Available**: False
**CVSS Score**: 8.5
**CVSS Vector**: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
**Summary**:
- **Updated Summary**: Updated 2024-06-03 to clarify the potential impact scope for this vulnerability.
- **Vulnerability Description**: The WatchGuard Mobile VPN with SSL Client on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY/SYSTEM on the Windows machine where the VPN Client is installed.
**Affected Versions**: This issue affects the Mobile VPN with SSL Client from 11.0 up to and including 12.11.2.
**Resolution**: Resolved in the Mobile VPN with SSL Client version 12.11.3.
**Credits**: AKASEC
**Advisory Product List**:
- **Product Family**: Other Software
- **Product Branch**: SSL VPN
- **Product List**: SSL VPN
Zaproxy alias impedit expedita quisquam pariatur exercitationem. Nemo rerum eveniet dolores rem quia dignissimos.