CVE-2025-0140: GlobalProtect App: Non Admin User Can Disable the GlobalProtect App
An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a locally authenticated non administrative user to disable the app even if the GlobalProtect app configuration would not normally permit them to do so.
The GlobalProtect app on Windows, Linux, iOS, Android, Chrome OS and GlobalProtect UWP app are not affected.
Affected Software
Remediation
Mitigation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0140?
CVE-2025-0140 has been classified with a medium severity level due to its potential impact on the security of the GlobalProtect App on macOS and Linux.
How do I fix CVE-2025-0140?
To remediate CVE-2025-0140, upgrade to the latest version of the Palo Alto Networks GlobalProtect App that addresses this vulnerability.
Who is affected by CVE-2025-0140?
CVE-2025-0140 affects locally authenticated non-administrative users on macOS and Linux devices using specific versions of the Palo Alto Networks GlobalProtect App.
What are the affected versions in CVE-2025-0140?
Versions 6.3.3-h1, 6.2.8-h2, 6.3.0, 6.2.0, 6.1.0, and 6.0.0 of the Palo Alto Networks GlobalProtect App are affected by CVE-2025-0140.
What type of vulnerability is CVE-2025-0140?
CVE-2025-0140 is an incorrect privilege assignment vulnerability that allows unauthorized actions by non-administrative users.