CVE Database
/

CVE-2025-0118

Back to search

CVE-2025-0118

Published: Mar 12, 2025

Modified: Mar 12, 2025

PUBLISHED

Description

A vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a remote attacker to run ActiveX controls within the context of an authenticated Windows user. This enables the attacker to run commands as if they are a legitimate authenticated user. However, to exploit this vulnerability, the authenticated user must navigate to a malicious page during the GlobalProtect SAML login process on a Windows device. This issue does not apply to the GlobalProtect app on other (non-Windows) platforms.

VendorProductVersions

Palo Alto Networks

GlobalProtect App

unaffected
6.3.0 - < 6.3.3
affected
6.2.0 - < 6.2.5
affected
6.1.0 - < 6.1.6
affected
6.0.0 - < 6.0.11

Palo Alto Networks

GlobalProtect App

unaffected
All - < 6.3.3

Palo Alto Networks

GlobalProtect UWP App

unaffected
All

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now