CVE-2025-0120 Details
Description
A vulnerability with a privilege management mechanism in the Palo Alto Networks GlobalProtect™ app on Windows devices allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. However, execution requires that the local user can also successfully exploit a race condition, which makes this vulnerability difficult to exploit.
A privilege escalation vulnerability has been identified in the Palo Alto Networks GlobalProtect app for Windows. This vulnerability allows a locally authenticated non-administrative user to escalate privileges to NT AUTHORITY\SYSTEM. The exploitation requires successfully navigating a race condition, which adds complexity to the attack.
Users can upgrade to GlobalProtect App 6.3.3 or later, 6.2.7-1077 or 6.2.8 or later. For GlobalProtect App 6.1 or 6.0 on Windows, upgrade to 6.2.8 or later or 6.3.3 or later. No action is needed for GlobalProtect App on macOS, Linux, iOS, Android, or the UWP version.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 11, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.paloaltonetworks.com/CVE-2025-0120 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-250 | Execution with Unnecessary Privileges | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| paloaltonetworks globalprotect | >= 6.0.0, < 6.0.12 >= 6.1.0, < 6.2.7-1077 >= 6.3.0, < 6.3.3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 27, 2025 | Initial Analysis | [email protected] |
| Apr 11, 2025 | New CVE Received | [email protected] |