Credential Manager is a place where credentials in the OS are can be stored for specific domain resources based on the targetname of the resource. This client certificate must contain the user information either in the Subject or Subject Alt fields. To trigger a software upgrade, an unprivileged user must communicate with PanGPS over a local TCP connection. This is the first of a two-part series of blogs covering the exploitation of GlobalProtect for Windows. In the Credential Manager window locate any cached credentials that have the term "Outlook" in the name. In the details below click "Remove from vault. Microsoft virtualization-based security, also known as "VBS", is a feature of the Windows 10 and Windows Server 2016 operating systems. The reason for this is if multiple credential providers are enabled the only way to know is by logging out of the machine and logging back in to check until the Centrify Credential Provider is the one being used. To recap, the CrowdStrike ® Intelligence Advanced Research Team discovered two distinct vulnerabilities in the Windows, Linux and macOS versions of the Palo Alto Networks GlobalProtect VPN client (CVE-2019-17435, CVE-2019-17436). The GlobalProtect Agent consists of two components, PanGPS and PanGPA, of which PanGPS runs with elevated privileges so that it can perform privileged operations, such as upgrading the agent software. 