First published: Wed Apr 12 2023(Updated: )
A local file deletion vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a user to delete system files from the endpoint with elevated privileges through a race condition.
Credit: psirt@paloaltonetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Paloaltonetworks Globalprotect | >=5.2.0<5.2.13 | |
Paloaltonetworks Globalprotect | >=6.0.0<6.0.4 | |
Paloaltonetworks Globalprotect | =6.1.0 |
This issue is fixed in GlobalProtect app 5.2.13, GlobalProtect app 6.0.4, GlobalProtect app 6.1.1, and all later GlobalProtect app versions on Windows devices.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0006 is a local file deletion vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices.
A user can exploit CVE-2023-0006 by deleting system files from the endpoint with elevated privileges through a race condition.
CVE-2023-0006 affects Palo Alto Networks GlobalProtect versions 5.2.0 to 5.2.13, 6.0.0 to 6.0.4, and 6.1.0.
CVE-2023-0006 has a severity rating of 6.3, classified as medium.
You can find more information about CVE-2023-0006 on the Palo Alto Networks website: [https://security.paloaltonetworks.com/CVE-2023-0006](https://security.paloaltonetworks.com/CVE-2023-0006)