Description
An unquoted search path vulnerability in the Windows release of Global Protect Agent allows an authenticated local user with file creation privileges on the root of the OS disk (C:\) or to Program Files directory to gain system privileges. This issue affects Palo Alto Networks GlobalProtect Agent 5.0 versions before 5.0.5; 4.1 versions before 4.1.13 on Windows;
No analysis available yet.
Remediation
Vendor Solution
This issue is fixed in Global Protect Agent 5.0.5, Global Protect Agent 4.1.13 and all later versions.
Vendor Workaround
Do not grant file creation privileges on the root of the OS disk (C:\) or 'Program Files' directory to unprivileged users.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-12778 | An unquoted search path vulnerability in the Windows release of Global Protect Agent allows an authenticated local user with file creation privileges on the root of the OS disk (C:\) or to Program Files directory to gain system privileges. This issue affects Palo Alto Networks GlobalProtect Agent 5.0 versions before 5.0.5; 4.1 versions before 4.1.13 on Windows; |
References
| Link | Providers |
|---|---|
| https://security.paloaltonetworks.com/CVE-2020-1988 |
|
History
No history.
Status: PUBLISHED
Assigner: palo_alto
Published:
Updated: 2024-09-16T18:03:55.930Z
Reserved: 2019-12-04T00:00:00.000Z
Link: CVE-2020-1988
No data.
Status : Modified
Published: 2020-04-08T19:15:13.917
Modified: 2024-11-21T05:11:47.710
Link: CVE-2020-1988
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD