CVE-2025-0117
Published: Mar 12, 2025
Modified: Feb 26, 2026
Description
A reliance on untrusted input for a security decision in the GlobalProtect app on Windows devices potentially enables a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. GlobalProtect App on macOS, Linux, iOS, Android, Chrome OS and GlobalProtect UWP App are not affected.
| Vendor | Product | Versions |
|---|---|---|
Palo Alto Networks | GlobalProtect App | affected 6.3.0 - < 6.3.3affected 6.2.0 - < 6.2.6affected 6.1.0 - < 10.2.14affected 6.0.0 - < 10.1.14-h11 |
Palo Alto Networks | GlobalProtect App | unaffected All - < 6.3.3 |
Palo Alto Networks | GlobalProtect UWP App | unaffected All |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now