A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race condition.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-27383 | A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race condition. |
Fixes
Solution
This issue is fixed in GlobalProtect app 5.1.12, GlobalProtect app 6.0.8, GlobalProtect app 6.1.2, GlobalProtect app 6.2.1, and all later GlobalProtect app versions on Windows.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://security.paloaltonetworks.com/CVE-2024-2432 |
|
History
Fri, 26 Sep 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Paloaltonetworks
Paloaltonetworks globalprotect |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:windows:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.2.0:*:*:*:*:windows:*:* |
|
| Vendors & Products |
Paloaltonetworks
Paloaltonetworks globalprotect |
Status: PUBLISHED
Assigner: palo_alto
Published:
Updated: 2024-08-28T15:14:21.571Z
Reserved: 2024-03-13T16:19:26.854Z
Link: CVE-2024-2432
Updated: 2024-08-01T19:11:53.524Z
Status : Analyzed
Published: 2024-03-13T18:15:08.603
Modified: 2025-09-26T19:10:56.553
Link: CVE-2024-2432
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:23:30Z
EUVD