CVE-2025-4232

GlobalProtect: Authenticated Code Injection Through Wildcard on macOS

Severity
High 8.5
CVSS 4.0
Exploited
Not listed
EPSS
0.004
34.9th percentile
Discovered by
Third party
Published by the vendor
Published
Jun 12, 2025
Assigned by palo_alto

Description

An improper neutralization of wildcards vulnerability in the log collection feature of Palo Alto Networks GlobalProtect™ app on macOS allows a non administrative user to escalate their privileges to root.

Weakness: CWE-155

Affected products

Vendor Product Category Matched by
Palo Alto Networks GlobalProtect VPN & Remote Access cna-assigner
Vendor-reported affected versions (2)
  • Palo Alto Networks · GlobalProtect App
  • Palo Alto Networks · GlobalProtect App

Credit

Rutger Flohil

Vendor remediation

Version Minor Version Suggested Solution GlobalProtect App 6.3 on macOS 6.3.0 through 6.3.2 Upgrade to 6.3.3 or later. GlobalProtect App 6.2 on macOS6.2.0 through 6.2.8-h2Upgrade to 6.2.8-h2 [ETA June 2025] or 6.3.3 or later.GlobalProtect App 6.1 on macOSUpgrade to 6.2.8-h2 [ETA June 2025] or 6.3.3 or later.GlobalProtect App 6.0 on macOSUpgrade to 6.2.8-h2 [ETA June 2025] or 6.3.3 or later.GlobalProtect App on Windows No action needed.GlobalProtect App on Linux No action needed.GlobalProtect App on Android No action needed.GlobalProtect App on iOS No action needed.GlobalProtect App on Chrome OS No action needed.