Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Marc Barrantes

#33049of 53,635
7.8Total CVSS
Vulnerabilities · 1
PT-2024-7800
7.8
2024-10-03
Microsoft · Windows · CVE-2024-9473
**Name of the Vulnerable Software and Affected Versions** Palo Alto Networks GlobalProtect App versions prior to 6.2.5 **Description** A privilege escalation issue in the Palo Alto Networks GlobalProtect app on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY/SYSTEM through the use of the repair functionality offered by the .msi file used to install GlobalProtect. **Recommendations** Update to version 6.2.5 to resolve the issue. As a temporary workaround, consider disabling the repair functionality offered by the .msi file used to install GlobalProtect until a patch is available. Restrict access to the .msi file used to install GlobalProtect to minimize the risk of exploitation.