Back to Database
Status published
High
CVE-2025-7012
Cato Networks Linux Client Local Privilege Escalation via Symlink
Vulnerability Description
An issue in Cato Networks' CatoClient for Linux, before version 5.5, allows a local attacker to escalate privileges to root by exploiting improper symbolic link handling.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-7012
Credits & Attribution
No credits recorded in the NVD database.
More from Cato Networks
View All →CVE-2025-3886
CatoNetworks CatoClient up to 5.8 PrivilegedHelperTool Race Condition
Medium
5.7
CVE-2025-14213
Cato's Socket WebUI is vulnerable to OS Command Injection
High
8.3
CVE-2024-6978
Cato Networks Windows SDP Client Local root certificates can be installed by low-privileged users
Medium
5.6
CVE-2024-6977
Cato Networks Windows SDP Client Sensitive data in trace logs can lead to account takeover
Medium
6.5
CVE-2024-6975
Cato Networks Windows SDP Client Local Privilege Escalation via openssl configuration file
High
8.8
Affected Vendor
Cato Networks
View all reports →Affected Software
Cato Client
Vulnerable Versions:
5.0
Timeline
Official Publish:
July 13th, 2025
Last Modified:
July 14th, 2025
Added to House:
July 22nd, 2026