In plain language
What this advisory means
A medium-severity security vulnerability was found in the Palo Alto Networks GlobalProtect app. This flaw lets a local non-administrative user gain full administrative control on Windows, macOS, and Linux computers. It means someone with limited access can run commands as if they were an administrator, which can harm your device's security. The issue does not affect GlobalProtect on iOS, Android, or ChromeOS.
Technical explanation
How the issue affects the environment
The vulnerability involves multiple local privilege escalation flaws within the GlobalProtect app. An attacker with local access can exploit these to escalate privileges to NT AUTHORITY\SYSTEM on Windows or root on macOS and Linux. The root cause relates to an untrusted search path (CWE-426), enabling exploitation without special configuration or user interaction. The flaw requires only low attacker privileges and low attack complexity, but allows executing arbitrary commands with high privileges. Fixed versions for affected OS and app versions have been released by Palo Alto Networks.
Operational impact
Why teams should care
If unpatched, this vulnerability allows attackers with local access to gain full administrative privileges. This elevation of privilege can compromise the confidentiality, integrity, and availability of systems running GlobalProtect. It escalates risk of unauthorized control that could lead to data loss, system disruption, or wider network compromise. Organizations relying on GlobalProtect on impacted desktop platforms should upgrade promptly to reduce exposure.
Immediate action
To remediate this vulnerability, upgrade to the fixed versions indicated for your operating system and GlobalProtect version. Additionally, upgrade PAN-OS and Prisma Access to their relevant fixed versions if applicable. This coordinated upgrade of both GlobalProtect clients and PAN-OS software is necessary to fully mitigate the risk. Contact Palo Alto Networks Support for on-demand upgrades if needed.
Affected and fixed releases
Temporary risk reduction
No known workarounds exist for this issue. Only upgrading to the fixed versions effectively mitigates the vulnerability.
Evidence and validation checklist
- Palo Alto Networks advisory states local privilege escalation vulnerabilities allow non-administrative users to gain SYSTEM/root privileges on desktop OS.
- Vulnerability requires only local access, no user interaction or special configuration.
- Fixed versions for GlobalProtect apps and PAN-OS provided with clear upgrade instructions.
- Severity rated MEDIUM with CVSS 5.9 and attack vector LOCAL, low complexity.
- No known exploits reported currently.
Authoritative reference
Palo Alto Networks Security Advisories
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
