CVE-2025-0117: Palo Alto Networks Globalprotect App

High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.

A reliance on untrusted input for a security decision in the GlobalProtect app on Windows devices potentially enables a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. GlobalProtect App on macOS, Linux, iOS, Android, Chrome OS and GlobalProtect UWP App are not affected.

Affected products

  • Palo Alto Networks Globalprotect App: from 6.3.0, before 6.3.3 (fixed in 6.3.3); from 6.2.0, before 6.2.6 (fixed in 6.2.6); from 6.1.0, before 10.2.14 (fixed in 10.2.14); from 6.0.0, before 10.1.14-h11 (fixed in 10.1.14-h11)
  • Palo Alto Networks Globalprotect Uwp App

Published 2025-03-12. Last modified 2026-06-17.