Where
AND
-Infinity
0
Severity
5.3
AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber

Multiple improper certificate validation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enables an attacker to intercept encrypted communications and potentially compromise the endpoint. This can enable a local non-administrative operating system user or an attacker on the same subnet to redirect traffic to an unauthorized server and facilitate the installation of malicious software.

The GlobalProtect app on Linux, Windows, iOS and GlobalProtect UWP app are not affected.

First published (updated )
Severity
7.1
AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H/E:U/AU:N/R:U/V:D/RE:M/U:Amber

A reliance on untrusted input for a security decision in the GlobalProtect app on Windows devices potentially enables a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM.

GlobalProtect App on Linux, iOS, Android, Chrome OS and GlobalProtect UWP App are not affected.

1 / 2
Source: MITRE

Remedy

No workaround or mitigation is available.

Remedy

VERSION SUGGESTED SOLUTION GlobalProtect App 6.3 on Windows Upgrade to 6.3.3 or later* GlobalProtect App 6.2 on Windows Upgrade to 6.2.6 or later* GlobalProtect App 6.1 on Windows Upgrade to 6.2.6 or later or upgrade to 6.3.3 or later* GlobalProtect App 6.0 on Windows Upgrade to 6.0.12 or later or upgrade to 6.2.6 or later or upgrade to 6.3.3 or later* GlobalProtect App on Linux No action needed GlobalProtect App on macOS No action needed GlobalProtect App on iOS No action needed GlobalProtect App on Android No action needed GlobalProtect UWP App No action needed * In addition to the software updates listed above, additional steps are required to protect against this vulnerability as described below. ** These steps are not needed for GlobalProtect app 6.2.8-h3 (6.2.8-c263) and later versions of GlobalProtect 6.2. Solution for new and existing GlobalProtect app installation on Windows You can use your endpoint mobile device management (MDM) tools to apply the following changes: 1. Install a fixed version of the GlobalProtect app. 2. Update the following registry key with the specified value (uses the REG_SZ type): [HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks\GlobalProtect\Settings] "check-communication"="yes" 3. Restart the operating system to apply this registry change. Alternate solution for new GlobalProtect app installation on Windows Install the GlobalProtect app with the pre-deployment key CHECKCOMM set to "yes": > msiexec.exe /i GlobalProtect64.msi CHECKCOMM="yes" Note: This command adds the registry value from the previous solution instructions—no additional MSI options are needed.
First published (updated )
Severity
8.4
AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H/E:U/AU:N/R:U/V:D/RE:M/U:Amber

An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on enables a locally authenticated non administrative user to escalate their privileges to root on macOS and Linux or NT AUTHORITY\SYSTEM on Windows.

The GlobalProtect app on iOS, Android, Chrome OS and GlobalProtect UWP app are not affected.

Remedy

No workaround or mitigation is available.

Remedy

VERSION MINOR VERSION SUGGESTED SOLUTION GlobalProtect App 6.3 on macOS 6.3.0 through 6.3.3 Upgrade to 6.3.3-h1 (6.3.3-c650) or later. GlobalProtect App 6.3 on Windows 6.3.0 through 6.3.3 Upgrade to 6.3.3-h1 (6.3.3-c650) or later. GlobalProtect App 6.2 on macOS 6.2.0 through 6.2.8 Upgrade to 6.2.8-h2 (6.2.8-c243) or later. GlobalProtect App 6.2 on Windows 6.2.0 through 6.2.8 Upgrade to 6.2.8-h2 (6.2.8-c243) or later. GlobalProtect App 6.1 on macOS Upgrade to 6.2.8-h2 (6.2.8-c243) or 6.3.3-h1 (6.3.3-c650) or later. GlobalProtect App 6.1 on Windows Upgrade to 6.2.8-h2 (6.2.8-c243) or 6.3.3-h1 (6.3.3-c650) or later. GlobalProtect App 6.0 on macOS Upgrade to 6.2.8-h2 (6.2.8-c243) or 6.3.3-h1 (6.3.3-c650) or later. GlobalProtect App 6.0 on Windows Upgrade to 6.2.8-h2 (6.2.8-c243) or 6.3.3-h1 (6.3.3-c650) or later. GlobalProtect App 6.2 on Linux 6.2.0 through 6.2.7 Upgrade to 6.2.8 or later. GlobalProtect App 6.1 on Linux Upgrade to 6.2.8 or later. GlobalProtect App 6.0 on Linux Upgrade to 6.2.8 or later. GlobalProtect App on Android, Chrome OS, iOS   No action needed. GlobalProtect UWP App No action needed.
First published (updated )
Severity
8.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber

An improper neutralization of wildcards vulnerability in the log collection feature of Palo Alto Networks GlobalProtect™ app on macOS allows a non administrative user to escalate their privileges to root.

Remedy

No workaround or mitigation is available.

Remedy

VERSION MINOR VERSION SUGGESTED SOLUTION GlobalProtect App 6.3 on macOS 6.3.0 through 6.3.2 Upgrade to 6.3.3 or later. GlobalProtect App 6.2 on macOS 6.2.0 through 6.2.8-223 Upgrade to 6.2.8-c243 or later. GlobalProtect App 6.1 on macOS Upgrade to 6.2.8-c243or 6.3.3 or later. GlobalProtect App 6.0 on macOS Upgrade to 6.2.8-c243 or 6.3.3 or later. GlobalProtect App on Windows No action needed. GlobalProtect App on Linux No action needed. GlobalProtect App on Android No action needed. GlobalProtect App on iOS No action needed. GlobalProtect App on Chrome OS   No action needed. 
First published (updated )
Severity
7.4
AV:A/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/U:Amber

An insufficient certificate validation issue in the Palo Alto Networks GlobalProtect™ app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating system user or an attacker on the same subnet to install malicious root certificates on the endpoint and subsequently install malicious software signed by the malicious root certificates on that endpoint.

Remedy

No known workarounds exist for this issue.

Remedy

VERSION MINOR VERSION SUGGESTED SOLUTION GlobalProtect App 6.3 on Windows 6.3.0 through 6.3.2 Upgrade to 6.3.2-h9 or 6.3.3-h2 or later*. GlobalProtect App 6.2 on Windows 6.2.0 through 6.2.8 Upgrade to 6.2.8-h3 or later*. GlobalProtect App 6.1 on Windows Upgrade to 6.2.8-h3 or 6.3.3-h2 or later*. GlobalProtect App 6.0 on Windows Upgrade to 6.2.8-h3 or 6.3.3-h2 or later*. GlobalProtect App 6.3 on Linux 6.3.0 through 6.3.2 Upgrade to 6.3.3 or later*. GlobalProtect App 6.2 on Linux Upgrade to 6.3.3 or later*. GlobalProtect App 6.1 on Linux Upgrade to 6.3.3 or later*. GlobalProtect App 6.0 on Linux Upgrade to 6.3.3 or later*. GlobalProtect App on Android, iOS, macOS No action needed. GlobalProtect UWP App   No action needed. * In addition to the software updates listed above, additional steps are required to protect against this vulnerability as described below: Solution for new and existing GlobalProtect app installation on Windows / Linux 1. Ensure the portal/gateway certificate can be validated using the operating system's certificate store (e.g., Local Machine Certificate Store or Current User Certificate Store in Windows; for Linux, refer to this documentation (https://docs.paloaltonetworks.com/globalprotect/6-2/globalprotect-app-user-guide/globalprotect-app-for-linux/support-for-native-certificate-store-for-prisma-access-and-globalprotect-app)). 2. Remove any certificates associated with portal/gateway validation from the "Trusted Root CA" list on the Portal.  3. Enable portal setting: “Enable Strict Certificate Check” (set FULLCHAINCERTVERIFY to yes).
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203