Palo Alto Security Update – 27 November 2024

Palo Alto has released security update to fix a vulnerability affecting Palo Alto GlobalProtect App.

The addressed vulnerability could allow the attacker to gain elevated privileges to the affected product.

GlobalProtect App Insufficient Certificate Validation Privilege Escalation Vulnerability (CVE-2024-5921):

  • CVSS v4.0: 5.6
  • Attack Vector: Adjacent
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Passive
  • Consequences: Privilege Escalation

It should be highlighted that a proof of concept for the mentioned vulnerability is publicly available.

Vulnerabilities

CVE-2024-5921

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Palo Alto Security Advisory

References