An insufficient policy enforcement vulnerability in Palo Alto Networks Prisma® Browser on Windows allows a locally authenticated non-admin user to bypass the screenshot control feature of the browser.


Browser self-protection should be enabled to mitigate this issue.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 14 Nov 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 14 Nov 2025 18:00:00 +0000

Type Values Removed Values Added
Description An insufficient policy enforcement vulnerability in Palo Alto Networks Prisma® Browser on Windows allows a locally authenticated non-admin user to bypass the screenshot control feature of the browser. Browser self-protection should be enabled to mitigate this issue.
Title Prisma Browser: Insufficient Policy Enforcement Vulnerability in Prisma Browser
Weaknesses CWE-424
References
Metrics cvssV4_0

{'score': 1.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/S:N/AU:N/R:U/V:D/RE:M/U:Amber'}


cve-icon MITRE

Status: PUBLISHED

Assigner: palo_alto

Published:

Updated: 2025-11-14T18:45:30.974Z

Reserved: 2025-05-12T22:05:15.363Z

Link: CVE-2025-4617

cve-icon Vulnrichment

Updated: 2025-11-14T18:45:28.357Z

cve-icon NVD

Status : Received

Published: 2025-11-14T18:15:47.547

Modified: 2025-11-14T18:15:47.547

Link: CVE-2025-4617

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.