Vulnerability Description
Forcepoint One DLP Client, version 23.04.5642 (and possibly newer versions), includes a restricted version of Python 2.5.4 that prevents use of the ctypes library. ctypes is a foreign function interface (FFI) for Python, enabling calls to DLLs/shared libraries, memory allocation, and direct code execution. It was demonstrated that these restrictions could be bypassed.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Forcepoint | One Data Loss Prevention | 23.04.5642 |
References
- https://kb.cert.org/vuls/id/420440Third Party Advisory
- https://support.forcepoint.com/s/article/000042256Permissions Required
- https://www.kb.cert.org/vuls/id/420440Third Party Advisory
FAQ
What is CVE-2025-14026?
CVE-2025-14026 is a vulnerability with a CVSS score of 7.8 (HIGH). Forcepoint One DLP Client, version 23.04.5642 (and possibly newer versions), includes a restricted version of Python 2.5.4 that prevents use of the ctypes library. ctypes is a foreign function interfa...
How severe is CVE-2025-14026?
CVE-2025-14026 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-14026?
Check the references section above for vendor advisories and patch information. Affected products include: Forcepoint One Data Loss Prevention.