CVE-2025-0120
A vulnerability with a privilege management mechanism in the Palo Alto Networks GlobalProtect™ app on Windows devices
A vulnerability with a privilege management mechanism in the Palo Alto Networks GlobalProtect™ app on Windows devices allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. However, execution requires that the local user can also successfully exploit a race condition, which makes this vulnerability difficult to exploit.
HIGH · CVSS 7
EPSS 0.00168
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0