CVE-2025-0117 Details
Description
A reliance on untrusted input for a security decision in the GlobalProtect app on Windows devices potentially enables a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. GlobalProtect App on macOS, Linux, iOS, Android, Chrome OS and GlobalProtect UWP App are not affected.
A vulnerability in the GlobalProtect app for Windows allows a locally authenticated non-administrative user to escalate privileges to NT AUTHORITY\SYSTEM. This issue arises from a reliance on untrusted input for security decisions. GlobalProtect apps on macOS, Linux, iOS, Android, Chrome OS, and the UWP version are not affected.
Users can upgrade to GlobalProtect App versions 6.3.3 or later, 6.2.6 or later, or for version 6.1, upgrade to 6.2.6 or later or 6.3.3 or later. After upgrading, it's necessary to update a specific registry key to ensure the vulnerability is fully addressed. This registry change can be applied using endpoint mobile device management tools. For new installations, the GlobalProtect app can be deployed with a pre-deployment key that automatically adds the required registry value.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 12, 2025CISA-ADP
Assessed Mar 13, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.paloaltonetworks.com/CVE-2025-0117 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-807 | Reliance on Untrusted Inputs in a Security Decision | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Palo Alto Networks GlobalProtect App | < 6.3.3 (semver) < 6.2.6 (semver) ~6.1 ~6.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 12, 2025 | New CVE Received | [email protected] |
Volerion