Home

Description

An incorrect privilege assignment vulnerability in Palo Alto Networks Autonomous Digital Experience Manager allows a locally authenticated low privileged user on macOS endpoints to escalate their privileges to root.

PUBLISHED Reserved 2024-12-20 | Published 2025-07-09 | Updated 2025-08-13 | Assigner palo_alto




MEDIUM: 6.3CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/AU:N/R:U/V:D/RE:M/U:Amber

Problem types

CWE-266 Incorrect Privilege Assignment

Product status

Default status
unaffected

5.6.0 (custom) before 5.6.7
affected

Timeline

2025-07-09:Initial Publication
2025-08-13:Updated the acknowledgment

Credits

Scott Gayou finder

References

security.paloaltonetworks.com/CVE-2025-0139 vendor-advisory

cve.org (CVE-2025-0139)

nvd.nist.gov (CVE-2025-0139)

Download JSON