#VU100915 Improper Certificate Validation in GlobalProtect app - CVE-2024-5921

 

#VU100915 Improper Certificate Validation in GlobalProtect app - CVE-2024-5921

Published: November 26, 2024


Vulnerability identifier: #VU100915
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-5921
CWE-ID: CWE-295
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
GlobalProtect app
Software vendor:
Palo Alto Networks, Inc.

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper certificate validation that enables attackers to connect the GlobalProtect app to arbitrary servers. A local user can force the application to connect to a malicious server, install malicious root certificates on the endpoint and subsequently install malicious software signed by the malicious root certificates on that endpoint.


Remediation

Install updates from vendor's website.

External links