PT-2025-25235 · Palo Alto Networks · Globalprotect

Rutger Flohil

·

Published

2025-06-11

·

Updated

2025-07-08

·

CVE-2025-4232

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Palo Alto Networks GlobalProtect versions prior to 6.2.8-h2 on macOS
Description An improper neutralization of wildcards vulnerability in the log collection feature of the Palo Alto Networks GlobalProtect app on macOS allows a non-administrative user to escalate their privileges to root. Public proof-of-concept code exists, and it is recommended to update now to protect the system.
Recommendations For versions prior to 6.2.8-h2 on macOS, update to version 6.2.8-h2 or later to resolve the issue. As a temporary workaround, consider restricting access to the log collection feature until a patch is applied. Avoid using the vulnerable log collection feature in the GlobalProtect app until the issue is resolved.

Fix

LPE

Improper Neutralization of Wildcards

Weakness Enumeration

Related Identifiers

BDU:2025-08772
CVE-2025-4232

Affected Products

Globalprotect