CVE-2025-0117Reliance on Untrusted Inputs in a Security Decision in Palo Alto Networks Globalprotect APP

Severity
7.1HIGHNVD
EPSS
0.1%
top 73.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 12

Description

A reliance on untrusted input for a security decision in the GlobalProtect app on Windows devices potentially enables a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. GlobalProtect App on macOS, Linux, iOS, Android, Chrome OS and GlobalProtect UWP App are not affected.

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H

Affected Packages3 packages

🔴Vulnerability Details

2
GHSA
GHSA-vhjm-w3vw-g6jw: A reliance on untrusted input for a security decision in the GlobalProtect app on Windows devices potentially enables a locally authenticated non-admi2025-03-12
CVEList
GlobalProtect App: Local Privilege Escalation (PE) Vulnerability2025-03-12

📋Vendor Advisories

1
Palo Alto
GlobalProtect App: Local Privilege Escalation (PE) Vulnerability
CVE-2025-0117 — Palo vulnerability | cvebase