PT-2025-28945 · Palo Alto Networks · Globalprotect Uwp App+1
CVSS v4.0
8.4
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber |
Name of the Vulnerable Software and Affected Versions:
Palo Alto Networks GlobalProtect App versions prior to 6.2.8-c243
Description:
An incorrect privilege assignment allows a locally authenticated, non-administrative user to escalate privileges to root on macOS and Linux, or NTAUTHORITY SYSTEM on Windows. The GlobalProtect app on iOS, Android, Chrome OS and GlobalProtect UWP app are not affected.
Recommendations:
Upgrade to GlobalProtect App version 6.2.8-c243.
Fix
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Globalprotect App
Globalprotect Uwp App