CVE-2025-0131: GlobalProtect App: Incorrect Privilege Management Vulnerability in OPSWAT MetaDefender Endpoint Security SDK (Severity: MEDIUM)
An incorrect privilege management vulnerability in the OPSWAT MetaDefender Endpoint Security SDK used by the Palo Alto Networks GlobalProtect™ app on Windows devices allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. However, execution requires that the local user also successfully exploits a race condition, which makes this vulnerability difficult to exploit.
Affected Software
Remediation
Mitigation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0131?
CVE-2025-0131 is classified as a high-severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2025-0131?
To mitigate CVE-2025-0131, ensure you update to a patched version of the OPSWAT MetaDefender Endpoint Security SDK beyond version 4.3.4451.
Who is affected by CVE-2025-0131?
CVE-2025-0131 affects locally authenticated non-administrative Windows users running specific versions of OPSWAT MetaDefender Endpoint Security SDK.
What type of vulnerability is CVE-2025-0131?
CVE-2025-0131 is an incorrect privilege management vulnerability that allows unauthorized privilege escalation.
What products are involved in CVE-2025-0131?
The affected product involved in CVE-2025-0131 is the OPSWAT MetaDefender Endpoint Security SDK used in the Palo Alto Networks GlobalProtect app.