Impact
The vulnerability allows a local user of the Palo Alto Networks GlobalProtect app to gain administrative privileges on Windows, macOS, and Linux. By exploiting the flaw, a non‑administrative user can achieve NT AUTHORITY\SYSTEM or root level access, enabling the execution of arbitrary commands with elevated rights.
Affected Systems
Affected products are the GlobalProtect app by Palo Alto Networks for Linux, macOS, and Windows. Exhibiting versions from 6.0.0 through 6.3.3‑h14 are vulnerable, including Windows, Linux, and macOS releases. PAN‑OS network firewalls running versions 10.2.x through 12.2.2, as well as Prism Access versions 10.2.x through 12.1.x, are also impacted. The iOS, Android, and ChromeOS editions of the GlobalProtect app are not affected.
Risk and Exploitability
The CVSS base score is 5.9, indicating moderate risk. No EPSS score is available and the vulnerability is not listed in CISA KEV. Exploitation requires local access to a device running a vulnerable GlobalProtect app or PAN‑OS version; a local user can then elevate privileges to system/root. The attack vector is local and does not require network connectivity, which limits exposure to systems with the application installed but still represents a significant privilege escalation risk.
OpenCVE Enrichment