First published: Thu Feb 10 2022(Updated: )
An improper handling of exceptional conditions vulnerability exists within the Connect Before Logon feature of the Palo Alto Networks GlobalProtect app that enables a local attacker to escalate to SYSTEM or root privileges when authenticating with Connect Before Logon under certain circumstances. This issue impacts GlobalProtect app 5.2 versions earlier than GlobalProtect app 5.2.9 on Windows and MacOS. This issue does not affect the GlobalProtect app on other platforms.
Credit: psirt@paloaltonetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Paloaltonetworks Globalprotect | >=5.2<5.2.9 | |
Apple macOS | ||
Microsoft Windows |
This issue is fixed in GlobalProtect app 5.2.9 on Windows and MacOS, and all later GlobalProtect app versions.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0016 is an improper handling of exceptional conditions vulnerability that exists within the Connect Before Logon feature of the Palo Alto Networks GlobalProtect app.
CVE-2022-0016 has a severity score of 7.8 (high).
The Palo Alto Networks GlobalProtect app versions 5.2 through 5.2.9 are affected by CVE-2022-0016.
A local attacker can escalate to SYSTEM or root privileges when authenticating with Connect Before Logon in the Palo Alto Networks GlobalProtect app under certain circumstances.
No, Apple macOS and Microsoft Windows are not vulnerable to CVE-2022-0016.