PT-2023-3283 · Microsoft+1 · Windows+2

Mohammad Arman

·

Published

2023-06-14

·

Updated

2023-07-31

·

CVE-2023-0009

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Palo Alto Networks GlobalProtect Agent (affected versions not specified)
Description The issue is related to errors in processing input data in the GlobalProtect Agent. It allows an attacker to execute arbitrary commands with elevated privileges. A local privilege escalation vulnerability in the Palo Alto Networks GlobalProtect app on Windows enables a local user or service account to execute programs with elevated privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2023-03417
CVE-2023-0009

Affected Products

Globalprotect
Palo Alto Networks Globalprotect
Windows