CVE-2025-0141 Details
Description
An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on enables a locally authenticated non administrative user to escalate their privileges to root on macOS and Linux or NT AUTHORITY\SYSTEM on Windows. The GlobalProtect app on iOS, Android, Chrome OS and GlobalProtect UWP app are not affected.
A privilege escalation vulnerability has been identified in the Palo Alto Networks GlobalProtect App on macOS, Linux, and Windows. This vulnerability allows a locally authenticated non-administrative user to escalate privileges to root on macOS and Linux, or to NT AUTHORITY\SYSTEM on Windows. The issue does not affect the GlobalProtect app on iOS, Android, Chrome OS, or the GlobalProtect UWP app.
Users can upgrade to GlobalProtect App version 6.3.3-h1 (6.3.3-c650) or later on macOS and Windows. For GlobalProtect App 6.2, users should upgrade to version 6.2.8-h2 (6.2.8-c243) or later on macOS, Windows, or Linux. Users on GlobalProtect App 6.1 or 6.0 on macOS, Windows, or Linux should upgrade to version 6.2.8-h2 (6.2.8-c243) or 6.3.3-h1 (6.3.3-c650) or later. The GlobalProtect apps on Android, Chrome OS, iOS, and the GlobalProtect UWP app do not require any action.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 9, 2025CISA-ADP
Assessed Jul 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.paloaltonetworks.com/CVE-2025-0141 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-426 | Untrusted Search Path | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Palo Alto Networks GlobalProtect App | >= 6.3.0, < 6.3.3-h1 (6.3.3-c650) >= 6.2.0, < 6.2.8 (semver) >= 6.1.0 (semver) >= 6.2.0, < 6.2.8-h2 (6.2.8-c243) >= 6.0.0 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 10, 2025 | CVE Modified | [email protected] |
| Jul 9, 2025 | New CVE Received | [email protected] |
Volerion