CVE-2025-0118
GlobalProtect App: Execution of Unsafe ActiveX Control Vulnerability
Description
A vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a remote attacker to run ActiveX controls within the context of an authenticated Windows user. This enables the attacker to run commands as if they are a legitimate authenticated user. However, to exploit this vulnerability, the authenticated user must navigate to a malicious page during the GlobalProtect SAML login process on a Windows device. This issue does not apply to the GlobalProtect app on other (non-Windows) platforms.
Weakness: CWE-618
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | GlobalProtect | VPN & Remote Access | cna-assigner |
Vendor-reported affected versions (3)
- Palo Alto Networks · GlobalProtect App
- Palo Alto Networks · GlobalProtect App
- Palo Alto Networks · GlobalProtect UWP App
Credit
Maxime ESCOURBIAC, Michelin CERT
Vendor remediation
The issue is addressed by hardening the browser embedded in GlobalProtect app to disallow ActiveX plugins. This security enhancement is implemented in patched versions of the GlobalProtect app, so upgrading resolves the issue. Version Suggested Solution GlobalProtect App 6.3 on Windows Upgrade to 6.3.3 or later GlobalProtect App 6.2 on Windows Upgrade to 6.2.5 or later GlobalProtect App 6.1 on WindowsUpgrade to 6.1.6 or later GlobalProtect App 6.0 on Windows Upgrade to 6.0.11 or later GlobalProtect App on macOSNo action neededGlobalProtect App on LinuxNo action neededGlobalProtect App on iOSNo action neededGlobalProtect App on AndroidNo action neededGlobalProtect UWP AppNo action needed