CVE-2021-3038: GlobalProtect App: Windows VPN kernel driver denial of service (DoS)
A denial-of-service (DoS) vulnerability in Palo Alto Networks GlobalProtect app on Windows systems allows a limited Windows user to send specifically-crafted input to the GlobalProtect app that results in a Windows blue screen of death (BSOD) error. This issue impacts: GlobalProtect app 5.1 versions earlier than GlobalProtect app 5.1.8; GlobalProtect app 5.2 versions earlier than GlobalProtect app 5.2.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Palo Alto Networks GlobalProtect app (Windows)to a version that resolves this vulnerability.Fixed in 5.1.8 - Upgrade
Upgrade
Palo Alto Networks GlobalProtect app (Windows)to a version that resolves this vulnerability.Fixed in 5.2.4
Event History
Frequently Asked Questions
What is CVE-2021-3038?
CVE-2021-3038 is a denial-of-service (DoS) vulnerability in Palo Alto Networks GlobalProtect app on Windows systems.
How does CVE-2021-3038 affect Palo Alto Networks GlobalProtect app?
CVE-2021-3038 allows a limited Windows user to send specifically-crafted input to the GlobalProtect app that results in a Windows blue screen of death (BSOD) error.
Which versions of Palo Alto Networks GlobalProtect app are affected by CVE-2021-3038?
CVE-2021-3038 impacts GlobalProtect app 5.1 versions between 5.1.0 and 5.1.8, as well as GlobalProtect app 5.2 versions between 5.2.0 and 5.2.4.
What is the severity of CVE-2021-3038?
CVE-2021-3038 has a severity rating of medium, with a severity value of 5.5.
Is there any additional information available on CVE-2021-3038?
Yes, you can find more information about CVE-2021-3038 at the following reference link: https://security.paloaltonetworks.com/CVE-2021-3038