一、 漏洞 CVE-2025-0118 基础信息
漏洞标题
GlobalProtect App: Execution of Unsafe ActiveX Control Vulnerability
来源:美国国家漏洞数据库 NVD
漏洞描述信息
A vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a remote attacker to run ActiveX controls within the context of an authenticated Windows user. This enables the attacker to run commands as if they are a legitimate authenticated user. However, to exploit this vulnerability, the authenticated user must navigate to a malicious page during the GlobalProtect SAML login process on a Windows device. This issue does not apply to the GlobalProtect app on other (non-Windows) platforms.
来源:美国国家漏洞数据库 NVD
CVSS信息
N/A
来源:美国国家漏洞数据库 NVD
漏洞类别
暴露的不安全ActiveX方法
来源:美国国家漏洞数据库 NVD
二、漏洞 CVE-2025-0118 的公开POC
# POC 描述 源链接 神龙链接
三、漏洞 CVE-2025-0118 的情报信息