CVE-2025-0141: GlobalProtect App: Privilege Escalation (PE) Vulnerability
An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on enables a locally authenticated non administrative user to escalate their privileges to root on macOS and Linux or NT AUTHORITY\SYSTEM on Windows.
The GlobalProtect app on iOS, Android, Chrome OS and GlobalProtect UWP app are not affected.
Affected Software
Remediation
Mitigation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0141?
CVE-2025-0141 has been assessed as a critical vulnerability due to its ability to allow a non-administrative user to escalate privileges to root.
How do I fix CVE-2025-0141?
To remediate CVE-2025-0141, upgrade the Palo Alto Networks GlobalProtect App to versions 6.3.3-h1 or 6.2.8-h2 or later.
Who is affected by CVE-2025-0141?
CVE-2025-0141 affects users of the Palo Alto Networks GlobalProtect App on macOS, Windows, and Linux platforms.
What systems are vulnerable to CVE-2025-0141?
CVE-2025-0141 affects the Palo Alto Networks GlobalProtect App versions up to 6.3.3-h1 and 6.2.8-h2.
Is there a workaround for CVE-2025-0141?
Currently, the best approach for CVE-2025-0141 is to update to the recommended version, as no alternative workarounds exist.