CVE-2026-33451
CVE-2026-33451 is an arbitrary read/write vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can send malformed data to an API and elevate their level of privilege to system.
View on NVDAnalysis
Absolute Secure Access (formerly NetMotion) is a standard enterprise VPN and ZTNA solution. A local privilege escalation to SYSTEM in a security client is a high-impact finding for enterprise IT environments, even if it requires an initial foothold on the machine.
Severity
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HCWE-125EPSS
Affects
absolute:secure_accessmicrosoft:windowsTechnical description
CVE-2026-33451 is an arbitrary read/write vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can send malformed data to an API and elevate their level of privilege to system.