CVE-2024-5921: GlobalProtect App: Insufficient Certificate Validation Leads to Privilege Escalation (Severity: MEDIUM)
An insufficient certification validation issue in the Palo Alto Networks GlobalProtect app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating system user or an attacker on the same subnet to install malicious root certificates on the endpoint and subsequently install malicious software signed by the malicious root certificates on that endpoint.
Please subscribe to our RSS feed https://security.paloaltonetworks.com/rss.xml to be alerted to new updates to this and other advisories.
Other sources
An insufficient certification validation issue in the Palo Alto Networks GlobalProtect app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating system user or an attacker on the same subnet to install malicious root certificates on the endpoint and subsequently install malicious software signed by the malicious root certificates on that endpoint.
Please subscribe to our RSS feed (https://security.paloaltonetworks.com/rss.xml) to be alerted to new updates to this and other advisories.
— Palo Alto Networks
Affected Software
Remediation
Mitigation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5921?
CVE-2024-5921 has a high severity rating due to its potential to enable unauthorized connections to malicious servers.
How do I fix CVE-2024-5921?
To remediate CVE-2024-5921, update the Palo Alto Networks GlobalProtect app to version 6.3.2 or later.
Which versions of GlobalProtect are affected by CVE-2024-5921?
CVE-2024-5921 affects versions up to 6.3.2, including 6.2.6 and lower versions.
What type of attacks does CVE-2024-5921 enable?
CVE-2024-5921 enables attackers to connect the GlobalProtect app to arbitrary servers, potentially leading to malware installation.
Who is largely impacted by CVE-2024-5921?
Local non-administrative operating system users or attackers on the same subnet using the vulnerable GlobalProtect app are largely impacted by CVE-2024-5921.