CVE-2024-5915: GlobalProtect App: Local Privilege Escalation (PE) Vulnerability (Severity: MEDIUM)
Published Aug 14, 2024
·Updated
A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges.
Affected Software
7 affected componentsFixes available
Palo Alto Networks Globalprotect Windows>=5.1.0<=5.1.9
Palo Alto Networks Globalprotect Windows>=6.0.0<=6.0.6
Palo Alto Networks Globalprotect Windows>=6.1.0<6.1.5
Palo Alto Networks Globalprotect Windows>=6.2.0<6.2.4
Palo Alto Networks Globalprotect Windows=6.3.0
All of the following
Palo Alto Networks GlobalProtect App<5.1.x, =5.1, <6.0.10-c826, =6.0, <6.1.5, =6.1, <6.2.4, =6.2, <6.3.1, =6.3
5.1.x (ETA: December 2024)6.0.10-c8266.1.56.2.46.3.1
Microsoft Windows*
Remediation
Information
This issue is fixed in GlobalProtect app 5.1.x (ETA: December 2024), GlobalProtect app 6.0.x (ETA: November 2024), GlobalProtect app 6.1.5, GlobalProtect app 6.2.4, GlobalProtect app 6.3.1 (ETA: end of August), and all later GlobalProtect app versions on Windows.
Mitigation
Ensure that the GlobalProtect installation directory and its contents cannot be modified by non-administrative Windows users.
Information
This issue is fixed in GlobalProtect app 5.1.x (ETA: December 2024), GlobalProtect app 6.0.10-c826, GlobalProtect app 6.1.5, GlobalProtect app 6.2.4, GlobalProtect app 6.3.1, and all later GlobalProtect app versions on Windows.
Event History
Aug 14, 2024
Advisory Published
via Palo Alto Networks·04:00 PM
CVE Published
via MITRE·04:40 PM
Data Sourced
via MITRE·04:40 PM
RemedyDescriptionWeakness
Nov 6, 2024
Advisory Published
via Palo Alto Networks·02:35 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-5915?
CVE-2024-5915 is classified as a privilege escalation vulnerability, which can lead to elevated privileges for a local user.
2
How do I fix CVE-2024-5915?
To fix CVE-2024-5915, upgrade your Palo Alto Networks GlobalProtect app to the latest recommended versions.
3
Who is affected by CVE-2024-5915?
CVE-2024-5915 affects users of specific versions of the Palo Alto Networks GlobalProtect app on Windows devices.
4
What versions of GlobalProtect are affected by CVE-2024-5915?
Versions 5.1.0 to 5.1.9, 6.0.0 to 6.0.6, 6.1.0 to 6.1.5, and 6.2.0 to 6.2.4 are affected by CVE-2024-5915.
5
Is CVE-2024-5915 present on all Windows devices?
No, CVE-2024-5915 specifically affects devices running vulnerable versions of the Palo Alto Networks GlobalProtect app.