CVE-2025-0118
Published: Mar 12, 2025
Modified: Mar 12, 2025
Description
A vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a remote attacker to run ActiveX controls within the context of an authenticated Windows user. This enables the attacker to run commands as if they are a legitimate authenticated user. However, to exploit this vulnerability, the authenticated user must navigate to a malicious page during the GlobalProtect SAML login process on a Windows device. This issue does not apply to the GlobalProtect app on other (non-Windows) platforms.
| Vendor | Product | Versions |
|---|---|---|
Palo Alto Networks | GlobalProtect App | unaffected 6.3.0 - < 6.3.3affected 6.2.0 - < 6.2.5affected 6.1.0 - < 6.1.6affected 6.0.0 - < 6.0.11 |
Palo Alto Networks | GlobalProtect App | unaffected All - < 6.3.3 |
Palo Alto Networks | GlobalProtect UWP App | unaffected All |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now