CVE-2024-9473: Palo Alto Networks Globalprotect
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
A privilege escalation vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY/SYSTEM through the use of the repair functionality offered by the .msi file used to install GlobalProtect.
Affected products
- Palo Alto Networks Globalprotect: from 5.1, before 6.2.5 (fixed in 6.2.5); version 6.3.0 only; version 6.3.1 only
Published 2024-10-09. Last modified 2026-06-17.