First published: Wed Jun 10 2020(Updated: )
A race condition vulnerability Palo Alto Networks GlobalProtect app on Windows allows a local limited Windows user to execute programs with SYSTEM privileges. This issue can be exploited only while performing a GlobalProtect app upgrade. This issue affects: GlobalProtect app 5.0 versions earlier than GlobalProtect app 5.0.10 on Windows; GlobalProtect app 5.1 versions earlier than GlobalProtect app 5.1.4 on Windows.
Credit: psirt@paloaltonetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Paloaltonetworks Globalprotect | >=5.0.0<5.0.10 | |
Paloaltonetworks Globalprotect | >=5.1.0<5.1.4 |
This issue is fixed in GlobalProtect app 5.0.10, GlobalProtect app 5.1.4, and all later GlobalProtect app versions.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-2032 is a race condition vulnerability in the Palo Alto Networks GlobalProtect app on Windows, allowing a local limited Windows user to execute programs with SYSTEM privileges.
CVE-2020-2032 affects GlobalProtect app 5.0 versions earlier than 5.0.10 and GlobalProtect app 5.1 versions earlier than 5.1.4 on Windows.
CVE-2020-2032 has a severity level of high.
CVE-2020-2032 can be exploited only during a GlobalProtect app upgrade.
Yes, upgrading to GlobalProtect app version 5.0.10 or 5.1.4 or later will fix the vulnerability.