CVE-2024-5915
GlobalProtect App: Local Privilege Escalation (PE) Vulnerability
Severity
Medium 5.2
CVSS 4.0
Exploited
Not listed
EPSS
0.002
11.5th percentile
Discovered by
Third party
Published by the vendor
Published
Aug 14, 2024
Assigned by palo_alto
Description
A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges.
Weakness: CWE-732
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | GlobalProtect | VPN & Remote Access | cna-assigner |
Vendor-reported affected versions (2)
- Palo Alto Networks · GlobalProtect App
- paloaltonetworks · globalprotect
Credit
Ashutosh Gautam/JumpThere
Vendor remediation
This issue is fixed in GlobalProtect app 5.1.x (ETA: December 2024), GlobalProtect app 6.0.x (ETA: November 2024), GlobalProtect app 6.1.5, GlobalProtect app 6.2.4, GlobalProtect app 6.3.1 (ETA: end of August), and all later GlobalProtect app versions on Windows.