CVE-2025-0118

GlobalProtect App: Execution of Unsafe ActiveX Control Vulnerability

Severity
Medium 6
CVSS 4.0
Exploited
Not listed
EPSS
0.004
34.7th percentile
Discovered by
Third party
Published by the vendor
Published
Mar 12, 2025
Assigned by palo_alto

Description

A vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a remote attacker to run ActiveX controls within the context of an authenticated Windows user. This enables the attacker to run commands as if they are a legitimate authenticated user. However, to exploit this vulnerability, the authenticated user must navigate to a malicious page during the GlobalProtect SAML login process on a Windows device. This issue does not apply to the GlobalProtect app on other (non-Windows) platforms.

Weakness: CWE-618

Affected products

Vendor Product Category Matched by
Palo Alto Networks GlobalProtect VPN & Remote Access cna-assigner
Vendor-reported affected versions (3)
  • Palo Alto Networks · GlobalProtect App
  • Palo Alto Networks · GlobalProtect App
  • Palo Alto Networks · GlobalProtect UWP App

Credit

Maxime ESCOURBIAC, Michelin CERT

Vendor remediation

The issue is addressed by hardening the browser embedded in GlobalProtect app to disallow ActiveX plugins. This security enhancement is implemented in patched versions of the GlobalProtect app, so upgrading resolves the issue.  Version Suggested Solution GlobalProtect App 6.3 on Windows Upgrade to 6.3.3 or later GlobalProtect App 6.2 on Windows Upgrade to 6.2.5 or later GlobalProtect App 6.1 on WindowsUpgrade to 6.1.6 or later GlobalProtect App 6.0 on Windows Upgrade to 6.0.11 or later GlobalProtect App on macOSNo action neededGlobalProtect App on LinuxNo action neededGlobalProtect App on iOSNo action neededGlobalProtect App on AndroidNo action neededGlobalProtect UWP AppNo action needed