Description
A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race condition.
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low
Affected products
- Palo Alto Networks / globalprotect_app5.1 – 5.1.12
- Palo Alto Networks / globalprotect_app6.0 – 6.0.8
- Palo Alto Networks / globalprotect_app6.1 – 6.1.2
- Palo Alto Networks / globalprotect_app6.2 – 6.2.1