CVE-2025-12690
Analyzed
Analyzed - Analysis Complete
Local Privilege Escalation in Forcepoint NGFW Engine
Publication date: 2026-03-11
Last updated on: 2026-05-07
Assigner: Forcepoint
Description
Description
Execution with unnecessary privileges in Forcepoint NGFW Engine allows local privilege escalation.This issue affects NGFW Engine through 6.10.19, through 7.3.0, through 7.2.4, through 7.1.10.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| forcepoint | next_generation_firewall | to 6.10.20 (exc) |
| forcepoint | next_generation_firewall | From 7.1.0 (inc) to 7.1.11 (exc) |
| forcepoint | next_generation_firewall | From 7.2.0 (inc) to 7.2.5 (exc) |
| forcepoint | next_generation_firewall | 7.3.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-250 | The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. |