Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gf7f-qj8g-pr38

Опубликовано: 13 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.2
CVSS3: 8.1

Описание

An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client.

The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected.

An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client.

The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected.

EPSS

Процентиль: 27%
0.00333
Низкий

5.2 Medium

CVSS4

8.1 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 8.1
nvd
около 1 месяца назад

An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client. The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected.

CVSS3: 9.8
fstec
около 1 месяца назад

Уязвимость компонента Pre-Logon Access Provider (PLAP) программного средства для обеспечения безопасного удаленного доступа к данным Palo Alto Networks GlobalProtect App, позволяющая нарушителю выполнять произвольный код

EPSS

Процентиль: 27%
0.00333
Низкий

5.2 Medium

CVSS4

8.1 High

CVSS3

Дефекты

CWE-94