Palo Alto Networks Family Security Update Advisory (CVE-2025-0141)

Palo Alto Networks Family Security Update Advisory (CVE-2025-0141)

Overview

 

Palo Alto Networks has released a security update that fixes vulnerabilities in the Palo Alto Networks family of products. Users of affected products are advised to update to the latest version.
 

 

Affected Products

 

CVE-2025-0141

 

GlobalProtect App 6.3 on macOS versions: 6.3.3-h1 (6.3.3-c650) and earlier
GlobalProtect App 6.3 on Windows version: before 6.3.3-h1 (6.3.3-c650)
GlobalProtect App 6.2 on macOS versions: 6.2.8-h2 (6.2.8-c243) and earlier
GlobalProtect App 6.2 on Windows version: less than 6.2.8-h2 (6.2.8-c243)
GlobalProtect App 6.2 on Linux version: less than 6.2.8
GlobalProtect App 6.1 on macOS, Windows, Linux versions: Full version
GlobalProtect App 6.0 on macOS, Windows, Linux versions: Full version

 

 

Resolved Vulnerabilities

 

Local privilege escalation vulnerability due to incorrect privilege assignment in GlobalProtect App (CVE-2025-0141)

 

 

Vulnerability Patches

Vulnerability Patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

CVE-2025-0141

 

GlobalProtect App 6.3 on macOS versions: 6.3.3-h1 (6.3.3-c650) and later
GlobalProtect App 6.3 on Windows version: 6.3.3-h1 (6.3.3-c650) or later
GlobalProtect App 6.2 on macOS version: 6.2.8-h2 (6.2.8-c243) or later
GlobalProtect App 6.2 on Windows version: 6.2.8-h2 (6.2.8-c243) or later
GlobalProtect App 6.1 on macOS, Windows: 6.2.8-h2 (6.2.8-c243) or later or 6.3.3-h1 (6.3.3-c650) or later
GlobalProtect App 6.0 on macOS, Windows: 6.2.8-h2 (6.2.8-c243) or later or 6.3.3-h1 (6.3.3-c650) or later
GlobalProtect App 6.2 on Linux version: 6.2.8 or later
GlobalProtect App 6.1 on Linux version: 6.2.8 or later
GlobalProtect App 6.0 on Linux version: 6.2.8 or later

 

 

References

 

[1] CVE-2025-0141 GlobalProtect App: Privilege Escalation (PE) Vulnerability
https://security.paloaltonetworks.com/CVE-2025-0141