CVE Vulnerabilities

CVE-2025-0135

Incorrect Privilege Assignment

Published: May 14, 2025 | Modified: Jun 27, 2025
CVSS 3.x
3.3
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtectâ„¢ App on macOS devices enables a locally authenticated non administrative user to disable the app.

The GlobalProtect app on Windows, Linux, iOS, Android, Chrome OS and GlobalProtect UWP app are not affected.

Weakness

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Globalprotect Paloaltonetworks 6.0.0 (including) 6.2.8 (excluding)
Globalprotect Paloaltonetworks 6.3.0 (including) 6.3.3 (excluding)

Potential Mitigations

References