Description
A race condition vulnerability Palo Alto Networks GlobalProtect app on Windows allows a local limited Windows user to execute programs with SYSTEM privileges. This issue can be exploited only while performing a GlobalProtect app upgrade. This issue affects: GlobalProtect app 5.0 versions earlier than GlobalProtect app 5.0.10 on Windows; GlobalProtect app 5.1 versions earlier than GlobalProtect app 5.1.4 on Windows.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
This issue is fixed in GlobalProtect app 5.0.10, GlobalProtect app 5.1.4, and all later GlobalProtect app versions.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-22058 | A race condition vulnerability Palo Alto Networks GlobalProtect app on Windows allows a local limited Windows user to execute programs with SYSTEM privileges. This issue can be exploited only while performing a GlobalProtect app upgrade. This issue affects: GlobalProtect app 5.0 versions earlier than GlobalProtect app 5.0.10 on Windows; GlobalProtect app 5.1 versions earlier than GlobalProtect app 5.1.4 on Windows. |
References
| Link | Providers |
|---|---|
| https://security.paloaltonetworks.com/CVE-2020-2032 |
|
History
No history.
Status: PUBLISHED
Assigner: palo_alto
Published:
Updated: 2024-09-17T02:27:10.850Z
Reserved: 2019-12-04T00:00:00.000Z
Link: CVE-2020-2032
No data.
Status : Modified
Published: 2020-06-10T18:15:11.780
Modified: 2024-11-21T05:24:30.247
Link: CVE-2020-2032
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD