Improper Certificate Validation in GlobalProtect app for Windows - CVE-2024-5921

 

Improper Certificate Validation in GlobalProtect app for Windows - CVE-2024-5921

Published: November 26, 2024


Vulnerability identifier: #VU100915
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-5921
CWE-ID: CWE-295
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper certificate validation that enables attackers to connect the GlobalProtect app to arbitrary servers. A local user can force the application to connect to a malicious server, install malicious root certificates on the endpoint and subsequently install malicious software signed by the malicious root certificates on that endpoint.


Affected software

GlobalProtect app for Windows

How to mitigate CVE-2024-5921

Install updates from vendor's website.

GlobalProtect app for Windows - update to 6.2.6

External References

Related Security Bulletins