CVE-2025-2179: GlobalProtect App: Non Admin User Can Disable the GlobalProtect App (Severity: MEDIUM)
An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on Linux devices enables a locally authenticated non administrative user to disable the app even if the GlobalProtect app configuration would not normally permit them to do so.
The GlobalProtect app on Windows, macOS, iOS, Android, Chrome OS and GlobalProtect UWP app are not affected.
Affected Software
Remediation
Mitigation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2179?
CVE-2025-2179 has been rated as a medium severity vulnerability due to its potential impact on application integrity.
Who is affected by CVE-2025-2179?
CVE-2025-2179 affects the Palo Alto Networks GlobalProtect App on Linux devices, specifically versions up to 6.2.9.
How do I fix CVE-2025-2179?
To address CVE-2025-2179, update the Palo Alto Networks GlobalProtect App to a version higher than 6.2.9.
What kind of attack does CVE-2025-2179 allow?
CVE-2025-2179 allows a locally authenticated non-administrative user to disable the GlobalProtect App inappropriately.
Is the GlobalProtect App on other operating systems affected by CVE-2025-2179?
No, CVE-2025-2179 specifically impacts the GlobalProtect App on Linux devices.