Palo Alto Networks GlobalProtect App
cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:macos:*:*
- >= 6.3.0, <= 6.3.2
- >= 6.2.0, <= 6.2.8-h2
- ~6.1
- ~6.0
A vulnerability allowing improper neutralization of wildcards has been identified in the log collection feature of the Palo Alto Networks GlobalProtect app for macOS. This vulnerability enables a non-administrative user to escalate privileges to root.
Exploitation of this vulnerability allows for unauthorized privilege escalation, enabling a non-administrative user to gain root access on the macOS system.
Users can upgrade to GlobalProtect App version 6.3.3 or later, or version 6.2.8-h2 (available June 2025).
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.