7 results (0.001 seconds)

CVSS: 7.8EPSS: 0%CPEs: 3EXPL: 0

14 Jun 2023 — A local privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows enables a local user to execute programs with elevated privileges. • https://security.paloaltonetworks.com/CVE-2023-0009 • CWE-807: Reliance on Untrusted Inputs in a Security Decision •

CVSS: 7.2EPSS: 0%CPEs: 2EXPL: 0

08 Apr 2020 — An unquoted search path vulnerability in the Windows release of Global Protect Agent allows an authenticated local user with file creation privileges on the root of the OS disk (C:\) or to Program Files directory to gain system privileges. This issue affects Palo Alto Networks GlobalProtect Agent 5.0 versions before 5.0.5; 4.1 versions before 4.1.13 on Windows; Una vulnerabilidad de ruta de búsqueda sin comillas en la versión de Windows del Global Protect Agent, permite a un usuario local autenticado con pr... • https://security.paloaltonetworks.com/CVE-2020-1988 • CWE-428: Unquoted Search Path or Element •

CVSS: 5.5EPSS: 0%CPEs: 2EXPL: 0

16 Oct 2019 — A Local Privilege Escalation vulnerability exists in the GlobalProtect Agent for Windows 5.0.3 and earlier, and GlobalProtect Agent for Windows 4.1.12 and earlier, in which the auto-update feature can allow for modification of a GlobalProtect Agent MSI installer package on disk before installation. Se presenta una vulnerabilidad de Escalada de Privilegios Local en GlobalProtect Agent para Windows versión 5.0.3 y anteriores, y GlobalProtect Agent para Windows versión 4.1.12 y anteriores, en la que la funcion... • https://security.paloaltonetworks.com/CVE-2019-17435 •

CVSS: 7.1EPSS: 0%CPEs: 4EXPL: 0

16 Oct 2019 — A Local Privilege Escalation vulnerability exists in GlobalProtect Agent for Linux and Mac OS X version 5.0.4 and earlier and version 4.1.12 and earlier, that can allow non-root users to overwrite root files on the file system. Se presenta una vulnerabilidad de Escalada de Privilegios Local en GlobalProtect Agent para Linux y Mac OS X versión 5.0.4 y anteriores y versión 4.1.12 y anteriores, lo que puede permitir que los usuarios no root sobrescriban los archivos root en el sistema de archivos. • https://security.paloaltonetworks.com/CVE-2019-17436 •

CVSS: 2.5EPSS: 0%CPEs: 2EXPL: 0

09 Apr 2019 — GlobalProtect Agent 4.1.0 for Windows and GlobalProtect Agent 4.1.10 and earlier for macOS may allow a local authenticated attacker who has compromised the end-user account and gained the ability to inspect memory, to access authentication and/or session tokens and replay them to spoof the VPN session and gain access as the user. GlobalProtect Agent versión 4.1.0 para Windows y GlobalProtect Agent versión 4.1.10 y anteriores para macOS pueden permitir un atacante autenticado local que haya comprometido la c... • http://www.securityfocus.com/bid/107868 • CWE-226: Sensitive Information in Resource Not Removed Before Reuse CWE-311: Missing Encryption of Sensitive Data •

CVSS: 7.2EPSS: 0%CPEs: 1EXPL: 0

11 Dec 2017 — Palo Alto Networks GlobalProtect Agent before 4.0.3 allows attackers with administration rights on the local station to gain SYSTEM privileges via vectors involving "image path execution hijacking." Palo Alto Networks GlobalProtect Agent en versiones anteriores a la 4.0.3 permite que atacantes con permisos de administración en la estación local obtengan privilegios SYSTEM mediante vectores relacionados con "image path execution hijacking". • http://www.securityfocus.com/bid/102083 •

CVSS: 5.9EPSS: 0%CPEs: 2EXPL: 0

31 Aug 2013 — Palo Alto Networks GlobalProtect before 1.1.7, and NetConnect, does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof portal servers and obtain sensitive information via a crafted certificate. Palo Alto Networks GlobalProtect anterior a 1.1.7 y NetConnect, no verifican los certificados X.509 desde los servidores SSL, lo que permite a atacantes man-in-the-middle suplantar a servidores y obtener información sensible a través de un certificado manipulado. • http://archives.neohapsis.com/archives/bugtraq/2012-10/0100.html • CWE-310: Cryptographic Issues •