CVE-2020-1988: Global Protect Agent: Local privilege escalation due to an unquoted search path vulnerability
An unquoted search path vulnerability in the Windows release of Global Protect Agent allows an authenticated local user with file creation privileges on the root of the OS disk (C:\) or to Program Files directory to gain system privileges. This issue affects Palo Alto Networks GlobalProtect Agent 5.0 versions before 5.0.5; 4.1 versions before 4.1.13 on Windows;
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Palo Alto Networks GlobalProtect Agentto a version that resolves this vulnerability.Fixed in 5.0.5 - Upgrade
Upgrade
Palo Alto Networks GlobalProtect Agentto a version that resolves this vulnerability.Fixed in 4.1.13
Event History
Frequently Asked Questions
What is CVE-2020-1988?
CVE-2020-1988 is an unquoted search path vulnerability in the Windows release of Global Protect Agent that allows an authenticated local user to gain system privileges.
How can an attacker exploit CVE-2020-1988?
An attacker can exploit CVE-2020-1988 by placing a malicious executable in an unquoted path that is used by the Global Protect Agent during startup, which can lead to arbitrary code execution with system privileges.
Which versions of Palo Alto Networks GlobalProtect Agent are affected by CVE-2020-1988?
Palo Alto Networks GlobalProtect Agent versions 4.1.0 to 4.1.13 and versions 5.0.0 to 5.0.5 are affected by CVE-2020-1988.
What is the severity of CVE-2020-1988?
CVE-2020-1988 has a severity rating of 6.7 (high).
How to fix CVE-2020-1988?
To fix CVE-2020-1988, it is recommended to update to the latest version of Palo Alto Networks GlobalProtect Agent, which contains the necessary patches and fixes for this vulnerability.