An unquoted search path vulnerability in the Windows release of Global Protect Agent allows an authenticated local user with file creation privileges on the root of the OS disk (C:\) or to Program Files directory to gain system privileges. This issue affects Palo Alto Networks GlobalProtect Agent 5.0 versions before 5.0.5; 4.1 versions before 4.1.13 on Windows;
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-12778 | An unquoted search path vulnerability in the Windows release of Global Protect Agent allows an authenticated local user with file creation privileges on the root of the OS disk (C:\) or to Program Files directory to gain system privileges. This issue affects Palo Alto Networks GlobalProtect Agent 5.0 versions before 5.0.5; 4.1 versions before 4.1.13 on Windows; |
Fixes
Solution
This issue is fixed in Global Protect Agent 5.0.5, Global Protect Agent 4.1.13 and all later versions.
Workaround
Do not grant file creation privileges on the root of the OS disk (C:\) or 'Program Files' directory to unprivileged users.
References
| Link | Providers |
|---|---|
| https://security.paloaltonetworks.com/CVE-2020-1988 |
|
History
No history.
Status: PUBLISHED
Assigner: palo_alto
Published:
Updated: 2024-09-16T18:03:55.930Z
Reserved: 2019-12-04T00:00:00
Link: CVE-2020-1988
No data.
Status : Modified
Published: 2020-04-08T19:15:13.917
Modified: 2024-11-21T05:11:47.710
Link: CVE-2020-1988
No data.
OpenCVE Enrichment
No data.
EUVD