CVE-2020-2032: GlobalProtect App: File race condition vulnerability leads to local privilege escalation during upgrade
A race condition vulnerability Palo Alto Networks GlobalProtect app on Windows allows a local limited Windows user to execute programs with SYSTEM privileges. This issue can be exploited only while performing a GlobalProtect app upgrade. This issue affects: GlobalProtect app 5.0 versions earlier than GlobalProtect app 5.0.10 on Windows; GlobalProtect app 5.1 versions earlier than GlobalProtect app 5.1.4 on Windows.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2020-2032?
CVE-2020-2032 is a race condition vulnerability in the Palo Alto Networks GlobalProtect app on Windows, allowing a local limited Windows user to execute programs with SYSTEM privileges.
How does CVE-2020-2032 affect GlobalProtect app?
CVE-2020-2032 affects GlobalProtect app 5.0 versions earlier than 5.0.10 and GlobalProtect app 5.1 versions earlier than 5.1.4 on Windows.
How severe is CVE-2020-2032?
CVE-2020-2032 has a severity level of high.
How can CVE-2020-2032 be exploited?
CVE-2020-2032 can be exploited only during a GlobalProtect app upgrade.
Is there a fix for CVE-2020-2032?
Yes, upgrading to GlobalProtect app version 5.0.10 or 5.1.4 or later will fix the vulnerability.