Back to Database
Status published
Medium
CVE-2017-15870
Palo Alto Networks GlobalProtect Agent before 4.0.3 allows attackers with...
Vulnerability Description
Palo Alto Networks GlobalProtect Agent before 4.0.3 allows attackers with administration rights on the local station to gain SYSTEM privileges via vectors involving "image path execution hijacking."
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-15870
Credits & Attribution
No credits recorded in the NVD database.
References
More from paloaltonetworks
View All →CVE-2018-9337
The PAN-OS web interface administration page in PAN-OS 6.1.20 and...
Medium
5.4
CVE-2018-9335
The PAN-OS session browser in PAN-OS 6.1.20 and earlier, PAN-OS...
Medium
5.4
CVE-2018-9334
The PAN-OS management web interface page in PAN-OS 6.1.20 and...
Medium
5.5
CVE-2018-9242
The PAN-OS management web interface page in PAN-OS 6.1.20 and...
Medium
5.5
CVE-2018-7636
The URL filtering "continue page" hosted by PAN-OS 8.0.10 and...
Medium
6.1
Affected Vendor
paloaltonetworks
View all reports →Affected Software
globalprotect
Vulnerable Versions:
0
Timeline
Official Publish:
December 11th, 2017
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.