8.8 CVE-2025-4232

 

An improper neutralization of wildcards vulnerability in the log collection feature of Palo Alto Networks GlobalProtect™ app on macOS allows a non administrative user to escalate their privileges to root.
https://nvd.nist.gov/vuln/detail/CVE-2025-4232

Categories

CWE-155 : Improper Neutralization of Wildcards or Matching Symbols
As data is parsed, an injected element may cause the process to take unexpected actions.

References

psirt@paloaltonetworks.com


 

CPE

cpe start end
Configuration 1
cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:macos:*:* >= 6.0.0 < 6.2.8
cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:macos:*:* >= 6.3.0 < 6.3.3


REMEDIATION




EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url
No known exploits

Other Nist (github, ...)

Url
No known exploits


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
No entry