vulnerability
Palo Alto Networks GlobalProtect App: CVE-2017-15870: GlobalProtect App Vulnerability
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:L/AC:L/Au:N/C:C/I:C/A:C) | Dec 6, 2017 | May 21, 2025 | Mar 25, 2026 |
Severity
7
CVSS
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
Published
Dec 6, 2017
Added
May 21, 2025
Modified
Mar 25, 2026
Description
An "image path execution hijacking" vulnerability affects the Palo Alto Networks Global Protect Client. Exploitation of this issue requires the root privileges on the local station. An attacker could exploit this vulnerability to obtain a certain level of persistence on the compromised host. (ref # GPC-4401 / CVE-2017-15870)
Successful exploitation requires local administrative privileges.
This issue affects GlobalProtect App for macOS 4.0.2 and earlier
Successful exploitation requires local administrative privileges.
This issue affects GlobalProtect App for macOS 4.0.2 and earlier
Solution
palo-alto-networks-globalprotect-app-upgrade-latest
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.