PT-2019-4015 · Palo Alto Networks · Globalprotect Agent For Windows

Hanno Heinrichs

·

Published

2019-10-15

·

Updated

2023-03-23

·

CVE-2019-17435

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions GlobalProtect Agent for Windows versions 5.0.3 and earlier GlobalProtect Agent for Windows versions 4.1.12 and earlier
Description A Local Privilege Escalation issue exists in the auto-update feature of the GlobalProtect Agent for Windows, where an attacker can modify the GlobalProtect Agent MSI installer package on disk before installation due to insufficient access control. This can allow an attacker to elevate their privileges by loading a modified MSI package installer onto the disk before the application installation process.
Recommendations For GlobalProtect Agent for Windows versions 5.0.3 and earlier, update to a version later than 5.0.3 to resolve the issue. For GlobalProtect Agent for Windows versions 4.1.12 and earlier, update to a version later than 4.1.12 to resolve the issue. As a temporary workaround, consider restricting access to the auto-update feature until a patch is available.

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2019-04546
CVE-2019-17435

Affected Products

Globalprotect Agent For Windows