Improper Certificate Validation in GlobalProtect app for Windows - CVE-2025-2183

 

Improper Certificate Validation in GlobalProtect app for Windows - CVE-2025-2183

Published: August 14, 2025


Vulnerability identifier: #VU114078
CSH Severity: Medium
CVSS v4: 7.4 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-2183
CWE-ID: CWE-295
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to improper certificate validation. A remote attacker on the local network can install malicious root certificates on the endpoint and subsequently install malicious software signed by the malicious root certificates on that endpoint.


Affected software

GlobalProtect app for Windows

How to mitigate CVE-2025-2183

Install updates from vendor's website.

GlobalProtect app for Windows - addressed in versions 6.2.8-h3, 6.3.2-h9, 6.3.3, 6.3.3-h2

External References

Related Security Bulletins