CVE-2024-5915
GlobalProtect App: Local Privilege Escalation (PE) Vulnerability
Severity
Medium 5.2
CVSS 4.0
Exploited
Not listed
EPSS
0.002
11.7th percentile
Discovered by
Third party
Vendor-published field
Published
Aug 14, 2024
Assigned by palo_alto
Description
A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges.
Weakness: CWE-732
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | GlobalProtect | VPN & Remote Access | cna-assigner |
Vendor-reported products (2)
- Palo Alto Networks · GlobalProtect App
- paloaltonetworks · globalprotect
Credit
Ashutosh Gautam/JumpThere
Vendor remediation
This issue is fixed in GlobalProtect app 5.1.x (ETA: December 2024), GlobalProtect app 6.0.x (ETA: November 2024), GlobalProtect app 6.1.5, GlobalProtect app 6.2.4, GlobalProtect app 6.3.1 (ETA: end of August), and all later GlobalProtect app versions on Windows.