A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race condition.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-27383 | A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race condition. |
Fixes
Solution
This issue is fixed in GlobalProtect app 5.1.12, GlobalProtect app 6.0.8, GlobalProtect app 6.1.2, GlobalProtect app 6.2.1, and all later GlobalProtect app versions on Windows.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://security.paloaltonetworks.com/CVE-2024-2432 |
|
History
Sat, 27 Sep 2025 04:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Paloaltonetworks
Paloaltonetworks globalprotect |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:windows:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.2.0:*:*:*:*:windows:*:* |
|
| Vendors & Products |
Paloaltonetworks
Paloaltonetworks globalprotect |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: palo_alto
Published:
Updated: 2024-08-28T15:14:21.571Z
Reserved: 2024-03-13T16:19:26.854Z
Link: CVE-2024-2432
Updated: 2024-08-01T19:11:53.524Z
Status : Analyzed
Published: 2024-03-13T18:15:08.603
Modified: 2025-09-26T19:10:56.553
Link: CVE-2024-2432
No data.
OpenCVE Enrichment
Updated: 2025-07-13T07:23:30Z
Weaknesses
EUVD