CVE-2022-0017: GlobalProtect App: Improper Link Resolution Vulnerability Leads to Local Privilege Escalation
An improper link resolution before file access ('link following') vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows that enables a local attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges under certain circumstances. This issue impacts: GlobalProtect app 5.1 versions earlier than GlobalProtect app 5.1.10 on Windows. GlobalProtect app 5.2 versions earlier than GlobalProtect app 5.2.5 on Windows. This issue does not affect GlobalProtect app on other platforms.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-0017?
CVE-2022-0017 is an improper link resolution before file access vulnerability in the Palo Alto Networks GlobalProtect app on Windows.
What is the severity of CVE-2022-0017?
CVE-2022-0017 has a severity score of 7.8 (high).
What software is affected by CVE-2022-0017?
Palo Alto Networks GlobalProtect versions 5.1 through 5.1.10 and versions 5.2 through 5.2.5 on Windows are affected by CVE-2022-0017.
How can an attacker exploit CVE-2022-0017?
An attacker can exploit CVE-2022-0017 by following an improper link and executing arbitrary code with SYSTEM privileges.
Is Microsoft Windows affected by CVE-2022-0017?
No, Microsoft Windows is not vulnerable to CVE-2022-0017.