CVE-2024-9473
GlobalProtect App: Local Privilege Escalation (PE) Vulnerability
Description
A privilege escalation vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY/SYSTEM through the use of the repair functionality offered by the .msi file used to install GlobalProtect.
Weakness: CWE-250
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | GlobalProtect | VPN & Remote Access | cna-assigner |
Vendor-reported affected versions (6)
- Palo Alto Networks · GlobalProtect App
- paloaltonetworks · globalprotect
- paloaltonetworks · globalprotect
- paloaltonetworks · globalprotect
- paloaltonetworks · globalprotect
- paloaltonetworks · globalprotect
Credit
Michael Baer of SEC Consult Vulnerability Lab
Vendor remediation
This issue is fixed in GlobalProtect app 6.2.5, and will be fixed in the remaining supported versions of GlobalProtect app listed in the Product Status section. Updates will be published to this advisory as they become available. Customers who want to upgrade should reach out to customer support at https://support.paloaltonetworks.com .