CVE-2024-5921 - CVE House
Back to Database
Status published High CVE-2024-5921

GlobalProtect App: Insufficient Certificate Validation Leads to Privilege Escalation

Vulnerability Description

An insufficient certification validation issue in the Palo Alto Networks GlobalProtect app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating system user or an attacker on the same subnet to install malicious root certificates on the endpoint and subsequently install malicious software signed by the malicious root certificates on that endpoint. Please subscribe to our RSS feed https://security.paloaltonetworks.com/rss.xml to be alerted to new updates to this and other advisories.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-5921

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Maxime ESCOURBIAC, Michelin CERT
  • Yassine BENGANA, Abicom for Michelin CERT
  • Richard Warren and David Cash of AmberWolf

Affected Vendor

Palo Alto Networks

View all reports →

Affected Software

GlobalProtect App
Vulnerable Versions:
6.3.0, 6.2.0, 6.1.0, 6.0.0, 5.1.0

Timeline

Official Publish: November 27th, 2024
Last Modified: February 20th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)