CVE-2024-5915

GlobalProtect App: Local Privilege Escalation (PE) Vulnerability

Severity
Medium 5.2
CVSS 4.0
Exploited
Not listed
EPSS
0.002
11.5th percentile
Discovered by
Third party
Published by the vendor
Published
Aug 14, 2024
Assigned by palo_alto

Description

A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges.

Weakness: CWE-732

Affected products

Vendor Product Category Matched by
Palo Alto Networks GlobalProtect VPN & Remote Access cna-assigner
Vendor-reported affected versions (2)
  • Palo Alto Networks · GlobalProtect App
  • paloaltonetworks · globalprotect

Credit

Ashutosh Gautam/JumpThere

Vendor remediation

This issue is fixed in GlobalProtect app 5.1.x (ETA: December 2024), GlobalProtect app 6.0.x (ETA: November 2024), GlobalProtect app 6.1.5, GlobalProtect app 6.2.4, GlobalProtect app 6.3.1 (ETA: end of August), and all later GlobalProtect app versions on Windows.