GlobalProtect App: Local Privilege Escalation (PE) Vulnerability
Vulnerability Description
A vulnerability with a privilege management mechanism in the Palo Alto Networks GlobalProtect™ app on Windows devices allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. However, execution requires that the local user can also successfully exploit a race condition, which makes this vulnerability difficult to exploit.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-0120
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Maxime ESCOURBIAC, Michelin CERT
- Yassine BENGANA, Abicom for Michelin CERT
More from Palo Alto Networks
View All →Affected Vendor
Palo Alto Networks
View all reports →