An updated code has been issued to resolve a vulnerability in the Forcepoint VPN Client software for Windows.

Last week, researchers at SafeBreach Labs revealed a security flaw, codenamed CVE-2019-6145. Specifically, they said that this flaw could be used not only to increase hacker but also to maintain persistence on an infected system.
This issue exists in Forcepoint VPN Client for Windows software version 6.6.0 or earlier, and is rated at a severity level of 6.5.
In the VPN client software, formerly known as Stonesoft VPN Client, a coding issue meant that during boot sequences on Windows , the VPN incorrectly attempted to run programs from C:\Program.exe and C:\Program Files (x86)\Forcepoint\VPN.exe. The client runs the Windows service sgvpn.exe as NT AUTHORITY\SYSTEM, which requires administrator privileges.
Now, if the hacker manages to create malware in any of these locations, the software will automatically execute it and this will give the cybercriminal more system-level capabilities.

It is worth noting that in order for a hacker to exploit the vulnerability, they must already have administrator privileges.
The SafeBreach Labs team, to test the vulnerability, crafted an .exe file. When such a version of the VPN was released, the file was executed as NT AUTHORITY\SYSTEM by the Forcepoint application
The researchers reported their findings to Forcepoint on September 5, and the company confirmed the validity of the vulnerability the same day. A CVE was issued on September 16, and after a patch was released, Forcepoint published security guidance on September 19.
For all of the above, experts recommend that Forcepoint VPN users update to version 6.6.1, if not newer, to be as protected as possible.
