Home
HIGH: 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/AU:N/R:U/V:D/RE:M/U:AmberDefault status
unaffected
6.3 (custom) before 6.3.3
affected
6.2.0 (custom) before 6.2.8-h2
affected
6.1.0 (custom)
affected
6.0.0 (custom)
affected
Default status
unaffected
All (custom)
unaffected
Description
An improper neutralization of wildcards vulnerability in the log collection feature of Palo Alto Networks GlobalProtect™ app on macOS allows a non administrative user to escalate their privileges to root.
Problem types
CWE-155: Improper Neutralization of Wildcards or Matching Symbols
Product status
6.3 (custom) before 6.3.3
6.2.0 (custom) before 6.2.8-h2
6.1.0 (custom)
6.0.0 (custom)
All (custom)
Timeline
| 2025-06-11: | Initial Publication |
Credits
Rutger Flohil
References
security.paloaltonetworks.com/CVE-2025-4232