An unquoted search path vulnerability in the Windows release of Global Protect Agent allows an authenticated local user with file creation privileges on the root of the OS disk (C:) or to Program Files directory to gain system privileges. This issue affects Palo Alto Networks GlobalProtect Agent 5.0 versions before 5.0.5; 4.1 versions before 4.1.13 on Windows;
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1988
Reference (s):
- https://security.paloaltonetworks.com/CVE-2020-1988