vulnerability

Palo Alto Networks GlobalProtect App: CVE-2022-0016: Privilege Escalation Vulnerability When Using Connect Before Logon With SAML Authentication

Severity
6
CVSS
(AV:L/AC:H/Au:N/C:C/I:C/A:C)
Published
Feb 9, 2022
Added
May 21, 2025
Modified
Jun 12, 2025

Description

An improper handling of exceptional conditions vulnerability exists within the Connect Before Logon feature of the Palo Alto Networks GlobalProtect app when the feature is configured to use SAML authentication that enables a local attacker to escalate to SYSTEM or root privileges when authenticating with Connect Before Logon under certain circumstances.

Solution

palo-alto-networks-globalprotect-app-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.