CVE-2025-14026: Forcepoint DLP Flaw Lets Attackers Unchain Restricted Python
ID: fdde5280-50c1-5d84-ae5a-fb15a1287c01
STIX ID: report--fdde5280-50c1-5d84-ae5a-fb15a1287c01
Feed Name: securityonline.info
A high-severity vulnerability (CVE-2025-14026, CVSS 7.8) was disclosed in the Forcepoint One DLP Client where a bundled legacy Python 2.5.4 runtime had its ctypes FFI removed as a mitigation but can be reconstructed by an attacker supplying compiled dependencies and patching ctypes.pyd, restoring the ability to execute arbitrary shellcode or DLLs. Exploitation could let attackers bypass DLP enforcement, disable monitoring, or alter client behavior on endpoints; Forcepoint fixed the issue by removing the vulnerable Python runtime in endpoint builds after version 23.11 and advises immediate upgrades.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
