GlobalProtect Agent 4.1.0 for Windows and GlobalProtect Agent 4.1.10 and earlier for macOS may allow a local authenticated attacker who has compromised the end-user account and gained the ability to inspect memory, to access authentication and/or session tokens and replay them to spoof the VPN session and gain access as the user.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: palo_alto

Published: 2019-04-09T21:04:01.397792Z

Updated: 2024-09-16T19:21:01.439Z

Reserved: 2018-12-06T00:00:00

Link: CVE-2019-1573

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-04-09T22:29:00.877

Modified: 2021-09-14T12:14:39.193

Link: CVE-2019-1573

cve-icon Redhat

No data.