CVE-2025-0117

Description

A reliance on untrusted input for a security decision in the GlobalProtect app on Windows devices potentially enables a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITYSYSTEM.GlobalProtect App on macOS, Linux, iOS, Android, Chrome OS and GlobalProtect UWP App are not affected.

Risk Information

Base Score
8.6
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C
EPSS Score
Exploitation Probability
0.034

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2025-0117 are fixed in GlobalProtect 6.2.6 (x64)Windows
Vulnerabilities CVE-2025-0117,CVE-2025-0118,CVE-2025-0120 are fixed in GlobalProtect (x64) (6.3.3)Windows
CVE-2025-0117NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-345039GlobalProtect (x64) (6.2.7)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234