CVE-2020-1989High

CVE-2020-1989 GlobalProtect App: Incorrect privilege assignment allows local privilege escalation

Published
April 8, 2020
Last Modified
April 8, 2020

🔗 CVE IDs covered (1)

📋 Description

An incorrect privilege assignment vulnerability when writing application-specific files in the Palo Alto Networks GlobalProtect App for Linux on ARM platform allows a local authenticated user to gain root privileges on the system. This issue affects Palo Alto Networks GlobalProtect App for Linux 5.0 versions before 5.0.8; 5.1 versions before 5.1.1.

🎯 Affected products1

  • GlobalProtect App

✅ Remediation

This issue is fixed in GlobalProtect App 5.0.8, GlobalProtect App 5.1.1 and all later versions. Workarounds and mitigations: There are no viable workarounds for this issue.

🔗 References (1)