First published: Wed Mar 13 2024(Updated: )
A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race condition.
Credit: psirt@paloaltonetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Palo Alto Networks GlobalProtect UWP App |
This issue is fixed in GlobalProtect app 5.1.12, GlobalProtect app 6.0.8, GlobalProtect app 6.1.2, GlobalProtect app 6.2.1, and all later GlobalProtect app versions on Windows.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-2432 is classified as a privilege escalation vulnerability.
To fix CVE-2024-2432, ensure that you are using the latest version of the Palo Alto Networks GlobalProtect app.
The potential impacts of CVE-2024-2432 include unauthorized execution of programs with elevated privileges on affected Windows devices.
CVE-2024-2432 affects local users of the Palo Alto Networks GlobalProtect app on Windows devices.
Exploitation of CVE-2024-2432 requires the local user to successfully exploit a race condition.