Where
AND
-Infinity
0
Severity
8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber

Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allow a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges.

The GlobalProtect app on iOS, Android, Chrome OS and GlobalProtect UWP app are not affected.

First published (updated )
Severity
8.5
AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber

Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges.

The GlobalProtect app on iOS, Android, and Chrome OS is not affected.

First published (updated )
Severity
8.4
AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H/E:U/AU:N/R:U/V:D/RE:M/U:Amber

An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on enables a locally authenticated non administrative user to escalate their privileges to root on macOS and Linux or NT AUTHORITY\SYSTEM on Windows.

The GlobalProtect app on iOS, Android, Chrome OS and GlobalProtect UWP app are not affected.

Remedy

No workaround or mitigation is available.

Remedy

VERSION MINOR VERSION SUGGESTED SOLUTION GlobalProtect App 6.3 on macOS 6.3.0 through 6.3.3 Upgrade to 6.3.3-h1 (6.3.3-c650) or later. GlobalProtect App 6.3 on Windows 6.3.0 through 6.3.3 Upgrade to 6.3.3-h1 (6.3.3-c650) or later. GlobalProtect App 6.2 on macOS 6.2.0 through 6.2.8 Upgrade to 6.2.8-h2 (6.2.8-c243) or later. GlobalProtect App 6.2 on Windows 6.2.0 through 6.2.8 Upgrade to 6.2.8-h2 (6.2.8-c243) or later. GlobalProtect App 6.1 on macOS Upgrade to 6.2.8-h2 (6.2.8-c243) or 6.3.3-h1 (6.3.3-c650) or later. GlobalProtect App 6.1 on Windows Upgrade to 6.2.8-h2 (6.2.8-c243) or 6.3.3-h1 (6.3.3-c650) or later. GlobalProtect App 6.0 on macOS Upgrade to 6.2.8-h2 (6.2.8-c243) or 6.3.3-h1 (6.3.3-c650) or later. GlobalProtect App 6.0 on Windows Upgrade to 6.2.8-h2 (6.2.8-c243) or 6.3.3-h1 (6.3.3-c650) or later. GlobalProtect App 6.2 on Linux 6.2.0 through 6.2.7 Upgrade to 6.2.8 or later. GlobalProtect App 6.1 on Linux Upgrade to 6.2.8 or later. GlobalProtect App 6.0 on Linux Upgrade to 6.2.8 or later. GlobalProtect App on Android, Chrome OS, iOS   No action needed. GlobalProtect UWP App No action needed.
First published (updated )
Severity
7.7
Buffer Overflow
AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber

A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man in the middle attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges. This vulnerability is triggered during the processing of requests and responses exchanged between Portal and Gateway.

The GlobalProtect app on iOS is not affected.

1 / 2
Source: MITRE
First published (updated )
Severity
7.7
Buffer Overflow
AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber

A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system processes and potentially execute arbitrary code with elevated privileges (SYSTEM privileges on Windows, and root privileges on macOS and Linux).

First published (updated )
Severity
7.7
Code Injection, Input Validation
AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber

An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client.

The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected.

1 / 2
Source: MITRE
First published (updated )
Severity
7.4
AV:A/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/U:Amber

An insufficient certificate validation issue in the Palo Alto Networks GlobalProtect™ app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating system user or an attacker on the same subnet to install malicious root certificates on the endpoint and subsequently install malicious software signed by the malicious root certificates on that endpoint.

Remedy

No known workarounds exist for this issue.

Remedy

VERSION MINOR VERSION SUGGESTED SOLUTION GlobalProtect App 6.3 on Windows 6.3.0 through 6.3.2 Upgrade to 6.3.2-h9 or 6.3.3-h2 or later*. GlobalProtect App 6.2 on Windows 6.2.0 through 6.2.8 Upgrade to 6.2.8-h3 or later*. GlobalProtect App 6.1 on Windows Upgrade to 6.2.8-h3 or 6.3.3-h2 or later*. GlobalProtect App 6.0 on Windows Upgrade to 6.2.8-h3 or 6.3.3-h2 or later*. GlobalProtect App 6.3 on Linux 6.3.0 through 6.3.2 Upgrade to 6.3.3 or later*. GlobalProtect App 6.2 on Linux Upgrade to 6.3.3 or later*. GlobalProtect App 6.1 on Linux Upgrade to 6.3.3 or later*. GlobalProtect App 6.0 on Linux Upgrade to 6.3.3 or later*. GlobalProtect App on Android, iOS, macOS No action needed. GlobalProtect UWP App   No action needed. * In addition to the software updates listed above, additional steps are required to protect against this vulnerability as described below: Solution for new and existing GlobalProtect app installation on Windows / Linux 1. Ensure the portal/gateway certificate can be validated using the operating system's certificate store (e.g., Local Machine Certificate Store or Current User Certificate Store in Windows; for Linux, refer to this documentation (https://docs.paloaltonetworks.com/globalprotect/6-2/globalprotect-app-user-guide/globalprotect-app-for-linux/support-for-native-certificate-store-for-prisma-access-and-globalprotect-app)). 2. Remove any certificates associated with portal/gateway validation from the "Trusted Root CA" list on the Portal.  3. Enable portal setting: “Enable Strict Certificate Check” (set FULLCHAINCERTVERIFY to yes).
First published (updated )
Severity
7.4
AV:A/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber

Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted.

The GlobalProtect app on iOS, Android, and Chrome OS is not affected.

First published (updated )
Severity
7.2
Race Condition
AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber

A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root.

The GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS is not affected.

First published (updated )
Severity
7.1
AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H/E:U/AU:N/R:U/V:D/RE:M/U:Amber

A reliance on untrusted input for a security decision in the GlobalProtect app on Windows devices potentially enables a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM.

GlobalProtect App on Linux, iOS, Android, Chrome OS and GlobalProtect UWP App are not affected.

1 / 2
Source: MITRE

Remedy

No workaround or mitigation is available.

Remedy

VERSION SUGGESTED SOLUTION GlobalProtect App 6.3 on Windows Upgrade to 6.3.3 or later* GlobalProtect App 6.2 on Windows Upgrade to 6.2.6 or later* GlobalProtect App 6.1 on Windows Upgrade to 6.2.6 or later or upgrade to 6.3.3 or later* GlobalProtect App 6.0 on Windows Upgrade to 6.0.12 or later or upgrade to 6.2.6 or later or upgrade to 6.3.3 or later* GlobalProtect App on Linux No action needed GlobalProtect App on macOS No action needed GlobalProtect App on iOS No action needed GlobalProtect App on Android No action needed GlobalProtect UWP App No action needed * In addition to the software updates listed above, additional steps are required to protect against this vulnerability as described below. ** These steps are not needed for GlobalProtect app 6.2.8-h3 (6.2.8-c263) and later versions of GlobalProtect 6.2. Solution for new and existing GlobalProtect app installation on Windows You can use your endpoint mobile device management (MDM) tools to apply the following changes: 1. Install a fixed version of the GlobalProtect app. 2. Update the following registry key with the specified value (uses the REG_SZ type): [HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks\GlobalProtect\Settings] "check-communication"="yes" 3. Restart the operating system to apply this registry change. Alternate solution for new GlobalProtect app installation on Windows Install the GlobalProtect app with the pre-deployment key CHECKCOMM set to "yes": > msiexec.exe /i GlobalProtect64.msi CHECKCOMM="yes" Note: This command adds the registry value from the previous solution instructions—no additional MSI options are needed.
First published (updated )
Severity
6.9
AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/AU:N/R:A/V:D/RE:M/U:Amber

An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the GlobalProtect app. After the passcode is known, the user can perform these actions even if the GlobalProtect app configuration would not normally permit them to do so.

First published (updated )
Severity
5.3
AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber

Multiple improper certificate validation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enables an attacker to intercept encrypted communications and potentially compromise the endpoint. This can enable a local non-administrative operating system user or an attacker on the same subnet to redirect traffic to an unauthorized server and facilitate the installation of malicious software.

The GlobalProtect app on Linux, Windows, iOS and GlobalProtect UWP app are not affected.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203