GlobalProtect 6.3.3-h14 (6.3.3-c1121) causes immediate PanGPA.exe crash (access violation) on Windows 11 25H2 after clean install — resolved by downgr

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

GlobalProtect 6.3.3-h14 (6.3.3-c1121) causes immediate PanGPA.exe crash (access violation) on Windows 11 25H2 after clean install — resolved by downgr

L0 Member

Summary
After installing GlobalProtect App 6.3.3-h14 (6.3.3-c1121) on Windows 11 25H2, the client crashes immediately and cannot be used to log in. Reverting to the previously installed version resolves the issue. This is not isolated to one machine — it has been reproduced on multiple independent Windows 11 25H2 endpoints.

Error observed
1. GlobalProtect warning dialog (yellow triangle)
2. Followed immediately by: GlobalProtect: PanGPA.exe - Application Error
"The instruction at 0x00007FF6A567AE06 referenced memory at 0x0000000000000040. The memory could not be read."

Environment
- OS: Windows 11 25H2
- GlobalProtect version: 6.3.3-h14 (6.3.3-c1121)
- Third-party AV: None (Windows Defender only)
- Domain/MDM managed: No (standalone/customer-side endpoints)

Troubleshooting performed
1. Full uninstall of GlobalProtect App via Control Panel
2. In Device Manager, the GlobalProtect Virtual Ethernet Adapter showed "Device is disabled (Code 22)"
3. Attempted to manually enable the device — doing so immediately triggered the same PanGPA.exe crash notification, and the adapter reverted back to a disabled state
4. Uninstalled the adapter with "Delete the driver software for this device" checked
5. Enabled "Show hidden devices" and confirmed no leftover entries under Network adapters or Non-Plug and Play Drivers
6. Rebooted
7. Performed a fresh reinstall of the 6.3.3-h14 MSI
8. Crash reproduced immediately on first launch after a clean install, with the virtual adapter again left in a disabled state — ruling out leftover/corrupted files from a prior install

Reproduction scope
Confirmed on at least two independent Windows 11 25H2 machines (internal test machine and a customer endpoint).

Working workaround
Downgrading GlobalProtect to the previously installed version restores normal function (login and connection both work).

Upgrade context
The upgrade to 6.3.3-h14 was performed in response to a Palo Alto security advisory.

Requesting
1. Confirmation on whether this is a known compatibility issue between GlobalProtect 6.3.3-h14 and Windows 11 25H2
2. A recommended fixed version or ETA
3. If no fix is currently available, guidance on whether staying on the downgraded version is safe from a security standpoint, and whether it leaves the endpoint exposed to the vulnerability the upgrade was meant to address螢幕擷取畫面 2026-09-22 162803.png螢幕擷取畫面 2026-09-22 162816.png

3 REPLIES 3

Community Team Member

Hi @a0983704304 ,

 

Is this for CVE-2026-0307 ?

LIVEcommunity team member
Stay Secure,
Jay
Don't forget to Like items if a post is helpful to you!

Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

L2 Linker

yes, but the version 1121 hab issues like versions before 1016. I think there are different contribution trees and the old bugs will always pop up in later versions 😞

Hi,  Is this for CVE-2026-0299 

  • 461 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!