GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake
A buffer overflow vulnerability exists in Palo Alto Networks GlobalProtect app during UDP tunnel handshake processing. An attacker positioned between the client and gateway (man-in-the-middle) can send a malformed response that overflows a buffer in the app, causing a denial of service or potentially executing arbitrary code with elevated privileges (SYSTEM on Windows, root on macOS/Linux). The vulnerability affects GlobalProtect versions below 6.3.3-h15 on Linux, below 6.3.3-h14 on macOS/Windows, below 6.3.5 on iOS/Android/Chrome OS, and below 6.0.15 on multiple platforms. The Linux version has no patch available.
- Network position to intercept UDP traffic between GlobalProtect client and gateway (man-in-the-middle capability)
- Client must initiate UDP tunnel connection attempt
- App must be below patched version for the target platform
Patching may require device reboot — plan for process interruption
/api/v1/advisories/1ca02f36-cef9-492f-a5ea-342ccb71475eGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.