CVE Vulnerabilities

CVE-2025-0135

Incorrect Privilege Assignment

Published: May 14, 2025 | Modified: Jun 27, 2025
CVSS 3.x
3.3
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtectâ„¢ App on macOS devices enables a locally authenticated non administrative user to disable the app.

The GlobalProtect app on Windows, Linux, iOS, Android, Chrome OS and GlobalProtect UWP app are not affected.

Weakness

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
GlobalprotectPaloaltonetworks6.0.0 (including)6.2.8 (excluding)
GlobalprotectPaloaltonetworks6.3.0 (including)6.3.3 (excluding)

Potential Mitigations

References