Impact
An improper input validation in the Windows Pre‑Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect App allows a man‑in‑the‑middle attacker to execute arbitrary code with SYSTEM privileges on an affected client. This flaw is a classic code‑injection weakness (CWE‑94). The impact is full system compromise on the victim machine, providing the attacker with the highest local privileges and the ability to run any code.
Affected Systems
Affected products are Palo Alto Networks GlobalProtect App on Windows. Versions 6.3.0 through 6.3.3‑h13, 6.2.0 through 6.2.8‑h12, and 6.0.0 through 6.0.14 are vulnerable. The app on Linux, macOS, iOS, Android, and Chrome‑OS is not affected.
Risk and Exploitability
The CVSS score is 5.2, indicating a moderate severity. The EPSS score is not provided, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, a remote attacker positioned as a MitM in the network can exploit the PLAP to run code with SYSTEM privileges. Successful exploitation requires network access to the vulnerable client and the ability to manipulate its authentication traffic. The lack of an EPSS score and KEV listing suggest that the vulnerability is not currently widely exploited, but the potential for local privilege escalation remains.
OpenCVE Enrichment