CVE-2020-1988 PUBLISHED CVSS 4.199999809265137 MEDIUM

An unquoted search path vulnerability in the Windows release of Global Protect Agent allows an authenticated local user with file creation privileges on the root of the OS disk (C:\) or to Program Files directory to gain system privileges. This issue affects Palo Alto Networks GlobalProtect Agent 5.0 versions before 5.0.5; 4.1 versions before 4.1.13 on Windows;

EPSS 0.13% · 32.5th percentile

Risk Scores

CVSS v3.1
4.199999809265137
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
EPSS Score
0.13%
32.5th percentile

Affected Products

VendorProductVersions
Palo Alto NetworksGlobal Protect Agent5.0, 4.1
paloaltonetworksglobalprotect4.1.0, 5.0.0

Timeline

References

Open in Interactive Console →