NA

CVE-2024-2432

Published: 13/03/2024 Updated: 13/03/2024

Vulnerability Summary

A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race condition.

Vulnerability Trend

Vendor Advisories

CVE-2024-2432 GlobalProtect App: Local Privilege Escalation (PE) Vulnerability ...

Github Repositories

CVE-2024-2432 Palo Alto GlobalProtect EoP On Windows system, it was found that GlobalProtect (App version 611-5 and 620-89) was vulnerable to arbitrary file delete with elevated privileges by symbolic link attack lead to local privilege escalation on local machine It was observed that when a Windows unprivileged user attempt to connect VPN with GlobalProtect, the process &