A vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices allows a man-in-the-middle attacker to execute arbitrary code with SYSTEM privileges. The issue is due to improper input validation in the Windows Pre-Logon Access Provider (PLAP) component. GlobalProtect apps on Linux, macOS, iOS, Android, and Chrome OS are not affected.
CVE-2017-5329 is a local privilege-escalation flaw in Palo Alto Networks Terminal Services Agent. NVD describes the issue as an out-of-bounds write (CWE-787) affecting versions before 7.0.7, with the vulnerable range shown as through 7.0.6. Because the attack is local, requires low privileges, and needs no user interaction, the practical risk is highest on systems where untrusted local users or code can r [truncated]
CVE-2017-5328 is a high-severity vulnerability in Palo Alto Networks Terminal Services Agent. According to the NVD record, versions before 7.0.7 are affected, and attackers may be able to spoof arbitrary users through unspecified vectors. The supplied NVD data rates the issue CVSS 7.5 (HIGH) with network attack complexity low and no user interaction required.