important · Privilege — GlobalProtect
A normal GlobalProtect user can execute commands as SYSTEM or root across three desktop platforms.
Affects
Palo Alto Networks GlobalProtect, the enterprise VPN and endpoint-access client for Windows, macOS, and Linux.
A non-administrative user influences a search path consumed by a privileged component, which resolves attacker-controlled content as SYSTEM on Windows or root on macOS and Linux.
Detail and 1 source
Only the 6.2 Windows and macOS fixes were already available on September 10; several other platform or release fixes still had future dates.
Chain to watch
A non-administrative user influences a GlobalProtect search path.→↓A privileged component resolves attacker-controlled content.→↓Commands run as SYSTEM or root.→↓Coverage remains incomplete across the affected platform and release matrix.
Unverified chainInventory GlobalProtect versions by platform and verify each platform-specific fixed release rather than treating the 6.2 Windows and macOS release as universal coverage.