CVE-2025-0117: Palo Alto Networks Globalprotect App
High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.
A reliance on untrusted input for a security decision in the GlobalProtect app on Windows devices potentially enables a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. GlobalProtect App on macOS, Linux, iOS, Android, Chrome OS and GlobalProtect UWP App are not affected.
Affected products
- Palo Alto Networks Globalprotect App: from 6.3.0, before 6.3.3 (fixed in 6.3.3); from 6.2.0, before 6.2.6 (fixed in 6.2.6); from 6.1.0, before 10.2.14 (fixed in 10.2.14); from 6.0.0, before 10.1.14-h11 (fixed in 10.1.14-h11)
- Palo Alto Networks Globalprotect Uwp App
Published 2025-03-12. Last modified 2026-06-17.