CVE-2024-5915

GlobalProtect App: Local Privilege Escalation (PE) Vulnerability

Severity
Medium 5.2
CVSS 4.0
Exploited
Not listed
EPSS
0.002
11.7th percentile
Discovered by
Third party
Vendor-published field
Published
Aug 14, 2024
Assigned by palo_alto

Description

A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges.

Weakness: CWE-732

Affected products

Vendor Product Category Matched by
Palo Alto Networks GlobalProtect VPN & Remote Access cna-assigner
Vendor-reported products (2)
  • Palo Alto Networks · GlobalProtect App
  • paloaltonetworks · globalprotect

Credit

Ashutosh Gautam/JumpThere

Vendor remediation

This issue is fixed in GlobalProtect app 5.1.x (ETA: December 2024), GlobalProtect app 6.0.x (ETA: November 2024), GlobalProtect app 6.1.5, GlobalProtect app 6.2.4, GlobalProtect app 6.3.1 (ETA: end of August), and all later GlobalProtect app versions on Windows.

Something wrong here?