- Description
- An improper neutralization of wildcards vulnerability in the log collection feature of Palo Alto Networks GlobalProtect™ app on macOS allows a non administrative user to escalate their privileges to root.
- Source
- psirt@paloaltonetworks.com
- NVD status
- Analyzed
CVSS 4.0
- Type
- Secondary
- Base score
- 8.5
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber
- Severity
- HIGH
CVSS 3.1
- Type
- Primary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- psirt@paloaltonetworks.com
- CWE-155
- Hype score
- Not currently trending
Palo Alto Networks fixed multiple privilege escalation flaws Palo Alto Networks has addressed multiple security flaws, including seven privilege escalation vulnerabilities and integrated 11 Chrome patches. The most severe issue, CVE-2025-4232 (CVSS 7.1), is a wildcard-based code
@dCypherIO
16 Jun 2025
40 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[CVE-2025-4232: HIGH] Security flaw in Palo Alto Networks GlobalProtect app for macOS allows unauthorized users to gain root access. Update now to protect your system.#cve,CVE-2025-4232,#cybersecurity https://t.co/eoKaSfZDTG https://t.co/CIekcYYiRe
@CveFindCom
12 Jun 2025
46 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:macos:*:*",
"vulnerable": true,
"matchCriteriaId": "B2DE8243-7786-4D7C-A0CB-A3D3E44C9B26",
"versionEndExcluding": "6.2.8",
"versionStartIncluding": "6.0.0"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:macos:*:*",
"vulnerable": true,
"matchCriteriaId": "EFAA1A23-5A3C-48FA-8672-D8329D67A14C",
"versionEndExcluding": "6.3.3",
"versionStartIncluding": "6.3.0"
}
],
"operator": "OR"
}
]
}
]