CVE-2025-0117: GlobalProtect App: Local Privilege Escalation (PE) Vulnerability
A reliance on untrusted input for a security decision in the GlobalProtect app on Windows devices potentially enables a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM.
GlobalProtect App on Linux, iOS, Android, Chrome OS and GlobalProtect UWP App are not affected.
Other sources
A reliance on untrusted input for a security decision in the GlobalProtect app on Windows devices potentially enables a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM.
GlobalProtect App on macOS, Linux, iOS, Android, Chrome OS and GlobalProtect UWP App are not affected.
— Palo Alto Networks
Affected Software
Remediation
Mitigation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0117?
CVE-2025-0117 is rated as high severity due to its potential for privilege escalation.
How do I fix CVE-2025-0117?
To remediate CVE-2025-0117, ensure you update the GlobalProtect App to the latest version released by Palo Alto Networks.
Who is affected by CVE-2025-0117?
CVE-2025-0117 affects Windows users of the GlobalProtect App, specifically versions prior to 6.3.3 and 6.2.6.
Can CVE-2025-0117 be exploited locally?
Yes, CVE-2025-0117 can be exploited by locally authenticated non-administrative users to escalate privileges.
Is the GlobalProtect App the only product affected by CVE-2025-0117?
Yes, CVE-2025-0117 specifically impacts the GlobalProtect App on Windows devices.