CVE-2025-0309 is a local privilege escalation vulnerability in Netskope Client for Windows caused by insufficient validation of the server connection endpoint. According to the provided description, the client does not adequately restrict or authenticate the server endpoint it connects to, and will accept connections to arbitrary servers presenting publicly signed CA TLS certificates. A local attacker can abuse this trust model by redirecting or inducing the Netskope Client to connect to an attacker-controlled server that uses a valid publicly trusted certificate, then return specially crafted responses that are processed in a way that results in privilege elevation on the local system.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a multi-component Windows exploit toolkit targeting the Netskope STAgent. It consists of three main projects: 1. **CustomAction (C++ DLL):** Implements a DLL with an exported Install function that, when triggered (e.g., via MSI custom action), calls PopThyShell to spawn a shell (cmd.exe) in the context of the active user session. This involves privilege escalation and token manipulation to launch the shell interactively. 2. **IPCProxy (C++ DLL):** Implements a TCP proxy server listening on 127.0.0.1:8888, forwarding traffic between a local client and a remote service (default 127.0.0.1:57130). It is designed to be injected into a process and facilitates communication between the controller and the agent. 3. **UpSkope (C# application):** Acts as the main controller. It can launch the agent process (nsdiag.exe), inject the proxy DLL, and communicate with the agent via the local proxy. It supports sending custom commands, including encrypted payloads, and can perform process injection and manipulation. The code includes routines for device fingerprinting (using BIOS serial, MachineGuid, etc.), encryption (AES with keys derived from device info and registry), and command serialization. The exploit chain involves process injection, privilege escalation, and local inter-process communication. The toolkit is operational and provides a working shell and command/control channel on a vulnerable system. The main attack vector is local, requiring code execution on the target machine. The code is modular and could be adapted for further weaponization.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.