CVE-2025-0141 describes an incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect App, specifically affecting macOS and Linux, and Windows platforms. This flaw allows a locally authenticated non-administrative user to escalate their privileges to root on macOS/Linux or NT AUTHORITY\SYSTEM on Windows. With a CVSS score of 8.4 (High), this vulnerability has a low attack complexity and requires local access, but can lead to significant impacts on system integrity and confidentiality. Currently, there is no public exploit code available, no evidence of active exploitation, and minimal community discussion or media coverage, indicating a low immediate threat level.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Palo Alto Networks | GlobalProtect App | >= 6.2.0, < 6.2.8, 6.0.0, 6.1.0CNA affecteddefault unaffected | |
| Palo Alto Networks | GlobalProtect App | >= 6.2.0, < 6.2.8-h2 (6.2.8-c243), >= 6.3.0, < 6.3.3-h1 (6.3.3-c650), 6.0.0, 6.1.0CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2025-0141 GlobalProtect App: Privilege Escalation (PE) Vulnerability
Jul 9, 2025CVE-2025-0141 GlobalProtect App: Privilege Escalation (PE) Vulnerability
Jul 9, 2025GlobalProtect App: Privilege Escalation (PE) Vulnerability
Jul 9, 2025GlobalProtect App: Privilege Escalation (PE) Vulnerability
Jul 9, 2025