CVE-2025-0131

GlobalProtect App: Incorrect Privilege Management Vulnerability in OPSWAT MetaDefender Endpoint Security SDK

Severity
High 7.1
CVSS 4.0
Exploited
Not listed
EPSS
0.001
3.9th percentile
Discovered by
Third party
Published by the vendor
Published
May 14, 2025
Assigned by palo_alto

Description

An incorrect privilege management vulnerability in the OPSWAT MetaDefender Endpoint Security SDK used by the Palo Alto Networks GlobalProtect™ app on Windows devices allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. However, execution requires that the local user also successfully exploits a race condition, which makes this vulnerability difficult to exploit.

Weakness: CWE-266

Affected products

Vendor Product Category Matched by

No product mapping yet — this CVE is pending taxonomy review.

Vendor-reported affected versions (1)
  • OPSWAT · MetaDefender Endpoint Security SDK

Credit

Palo Alto Networks thanks Maxime Escourbiac, Michelin CERT, Yassine Bengana, Abicom for Michelin CERT, and Sandro Poppi for discovering and reporting the issue. Palo Alto Networks thanks OPSWAT for remediating this issue in the MetaDefender Endpoint Security SDK.

Vendor remediation

This issue is fixed in MetaDefender Endpoint Security SDK 4.3.4451 on Windows, and all later MetaDefender Endpoint Security SDK versions on Windows. To mitigate this issue in the GlobalProtect App on Windows update to one of the listed versions (these versions include the updated MetaDefender Endpoint Security SDK): Version Suggested Solution GlobalProtect App 6.3 on WindowsUpgrade to 6.3.3 or laterGlobalProtect App 6.2 on Windows Upgrade to 6.2.8 or later GlobalProtect App 6.1 on Windows Upgrade to 6.2.8 or later or 6.3.3 or later GlobalProtect App 6.0 on Windows Upgrade to 6.2.8 or later or 6.3.3 or later GlobalProtect App on macOSNot applicableGlobalProtect App on LinuxNot applicableGlobalProtect App on iOSNot applicableGlobalProtect App on AndroidNot applicableGlobalProtect UWP AppNot applicable