SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-1988

An unquoted search path vulnerability in the Windows release of Global Protect Agent allows an authenticated local user with file creation privileges on the root of the OS disk (C:\) or to Program Files directory to gain system privileges.

MEDIUM 6.7EPSS 0.37%

Does this matter?

Lower severity and a low EPSS score (0.37%). Track it; it rarely justifies an emergency change on its own.

Description

An unquoted search path vulnerability in the Windows release of Global Protect Agent allows an authenticated local user with file creation privileges on the root of the OS disk (C:\) or to Program Files directory to gain system privileges. This issue affects Palo Alto Networks GlobalProtect Agent 5.0 versions before 5.0.5; 4.1 versions before 4.1.13 on Windows;

CVSS 3.1
6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
0.37% probability · 30th percentile
CISA KEV
Not listed
Weakness
CWE-428
Affected
paloaltonetworks/globalprotect
Source
psirt@paloaltonetworks.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.