#VU100915 Improper Certificate Validation in GlobalProtect app - CVE-2024-5921
Published: November 26, 2024
GlobalProtect app
Palo Alto Networks, Inc.
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper certificate validation that enables attackers to connect the GlobalProtect app to arbitrary servers. A local user can force the application to connect to a malicious server, install malicious root certificates on the endpoint and subsequently install malicious software signed by the malicious root certificates on that endpoint.