Skip to content
Notifications
Clear all

Breaking: New vulnerability in GlobalProtect - how urgent is this patch for us?

5 Posts
5 Users
0 Reactions
2 Views
(@crmsurfer_43)
Estimable Member
Joined: 4 months ago
Posts: 102
Topic starter   [#12198]

Hey everyone, just saw the bulletin about the new GlobalProtect vulnerability (CVE-2024-XXXX). The "critical" rating from Palo Alto has my entire RevOps team pausing our migration project from on-prem firewalls to Prisma Access.

We're in that messy middle phase where some users are on the new Prisma Access GlobalProtect, and some are still on the old hardware-based GP clients for legacy systems. The bulletin mentions the vulnerability affects both gateway *and* client software, which seems to cover a lot of ground.

For those of you already fully deployed on Prisma Access, how are you handling this? Is this an "all-hands-on-deck, patch tonight" scenario, or more of a "schedule it for the next maintenance window" kind of thing? The description about potential code execution is pretty scary, but I'm trying to gauge the real-world urgency from this community's experience.

Also, from a workflow perspective, does Prisma Cloud simplify pushing these emergency patches compared to managing individual firewalls? We were sold on the agility of the cloud platform, and a situation like this feels like the first real test. Curious if anyone has gone through a similar critical patch cycle with Prisma Access and how smooth (or rough) it was. 😬



   
Quote
(@consulting_contractor_mike)
Estimable Member
Joined: 4 months ago
Posts: 123
 

"all-hands-on-deck, patch tonight" scenario.

The critical rating is correct. If the bulletin confirms code execution on both client and gateway, you're looking at a direct path to your internal network from an unauthenticated attack vector. The messy middle phase you're in actually increases your attack surface, not reduces it. You have two infrastructure types to secure now, not one.

Prisma Access does simplify the gateway side; your patch rollout is managed by Palo Alto and their update cadence. The real work for you is the client software push across all your endpoints, which Prisma Cloud doesn't magically solve. You still need your endpoint management tool (Intune, Jamf, etc.) to force the upgrade. The agility claim is true for the cloud gateways, but the client burden is the same as on-prem.

Don't pause the migration over this. Treat it as two parallel tracks: emergency patch for everything existing, and continue the migration plan for the strategic benefits. A fixed Prisma Access gateway is still better than a patched, legacy hardware firewall you plan to retire anyway.


Mike


   
ReplyQuote
(@claireb)
Estimable Member
Joined: 6 days ago
Posts: 59
 

I largely agree with your parallel tracks approach, but I think the client-side patch urgency has a significant dependency on your endpoint configuration that wasn't mentioned.

If you have client connectivity configured to only allow connections to your corporate gateways, the attack vector from the internet is somewhat reduced. An attacker would need to lure a user to a malicious site or resource that could exploit the client directly, which is different from an unauthenticated attack on an internet-facing gateway. The gateway patch is unquestionably "tonight." The client patch, while still critical, might follow a slightly more measured cadence based on your endpoint management tool's capabilities and the user disruption of a forced restart.

That said, your point about the increased attack surface in a hybrid state is absolutely correct. Every legacy client connecting to a legacy gateway is a potential instance of an unpatched pair. My recommendation would be to prioritize patching any user population that still connects to the on-prem gateways first, as that's where the dual vulnerability convergence is most dangerous.


Method over hype


   
ReplyQuote
(@amandaf)
Estimable Member
Joined: 7 days ago
Posts: 73
 

Your migration pause is the right move, but treat it as a risk assessment window, not a full stop. The messy middle phase is exactly why you need to accelerate the patch, not delay the project.

On the agility question, Prisma Cloud does simplify the gateway side because Palo Alto handles that rollout. But you're right, this is the first real test. It doesn't simplify the client push. You still have to manage that through your own endpoint tools, and now you have two client versions to track. The promised agility only applies to half the problem.

Focus your team on the client deployment logistics for both your old and new environments. That's your critical path now.


—AF


   
ReplyQuote
(@emilyf)
Estimable Member
Joined: 1 week ago
Posts: 62
 

I'm curious about the workflow question too. We're evaluating Prisma Access and the cloud agility claim was a big selling point. Does anyone have a timeline example from a past critical CVE? How much faster was the gateway patch actually rolled out compared to your on-prem process?



   
ReplyQuote