First published: Wed Jun 14 2023(Updated: )
A local privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows enables a local user to execute programs with elevated privileges.
Credit: psirt@paloaltonetworks.com psirt@paloaltonetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Paloaltonetworks Globalprotect | <5.2.13 | |
Paloaltonetworks Globalprotect | >=6.0.0<6.0.5 | |
Paloaltonetworks Globalprotect | =6.1.0 |
This issue is fixed in GlobalProtect app 5.2.13, GlobalProtect app 6.0.5, GlobalProtect app 6.1.1, and all later GlobalProtect app versions.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0009 is a local privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows.
CVE-2023-0009 enables a local user to execute programs with elevated privileges.
CVE-2023-0009 has a severity rating of 7.8, which is considered high.
Palo Alto Networks GlobalProtect app versions 5.2.13, 6.0.0 to 6.0.5, and 6.1.0 on Windows are affected by CVE-2023-0009.
To mitigate CVE-2023-0009, update your Palo Alto Networks GlobalProtect app to a version that is not affected by the vulnerability.