CVE-2024-2432
GlobalProtect App: Local Privilege Escalation (PE) Vulnerability
Severity
Medium 4.5
CVSS 3.1
Exploited
Not listed
EPSS
0.004
31.4th percentile
Discovered by
Third party
Published by the vendor
Published
Mar 13, 2024
Assigned by palo_alto
Description
A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race condition.
Weakness: CWE-269
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | GlobalProtect | VPN & Remote Access | cna-assigner |
Vendor-reported affected versions (2)
- Palo Alto Networks · GlobalProtect App
- paloaltonetworks · globalprotect
Credit
Palo Alto Networks thanks Erwin Chan for discovering and reporting this issue.
Vendor remediation
This issue is fixed in GlobalProtect app 5.1.12, GlobalProtect app 6.0.8, GlobalProtect app 6.1.2, GlobalProtect app 6.2.1, and all later GlobalProtect app versions on Windows.