NONE · 0

CVE-2025-0117

A reliance on untrusted input for a security decision in the GlobalProtect app on Windows devices potentially enables a locally authenticated non-administrative Windows user to escalate their privileg...

Vulnerability Description

A reliance on untrusted input for a security decision in the GlobalProtect app on Windows devices potentially enables a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. GlobalProtect App on macOS, Linux, iOS, Android, Chrome OS and GlobalProtect UWP App are not affected.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-0117?

CVE-2025-0117 is a documented vulnerability. A reliance on untrusted input for a security decision in the GlobalProtect app on Windows devices potentially enables a locally authenticated non-administrative Windows user to escalate their privileg...

How severe is CVE-2025-0117?

CVSS scoring is not yet available for CVE-2025-0117. Check NVD for updates.

Is there a patch for CVE-2025-0117?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.