An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtectâ„¢ App on macOS devices enables a locally authenticated non administrative user to disable the app.
The GlobalProtect app on Windows, Linux, iOS, Android, Chrome OS and GlobalProtect UWP app are not affected.
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Globalprotect | Paloaltonetworks | 6.0.0 (including) | 6.2.8 (excluding) |
Globalprotect | Paloaltonetworks | 6.3.0 (including) | 6.3.3 (excluding) |