CVE-2024-5905

Cortex XDR Agent: Local Windows User Can Disrupt Functionality of the Agent

Severity
Low 2
CVSS 4.0
Exploited
Not listed
EPSS
0.001
0.5th percentile
Discovered by
Third party
Published by the vendor
Published
Jun 12, 2024
Assigned by palo_alto

Description

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local low privileged Windows user to disrupt some functionality of the agent. However, they are not able to disrupt Cortex XDR agent protection mechanisms using this vulnerability.

Weakness: CWE-346

Affected products

Vendor Product Category Matched by
Palo Alto Networks Cortex XDR Endpoint / EDR cna-assigner
Vendor-reported affected versions (1)
  • Palo Alto Networks · Cortex XDR Agent

Credit

Palo Alto Networks thanks Manuel Feifel of VUREX (InfoGuard AG) for discovering and reporting this issue.

Vendor remediation

This issue is fixed in Cortex XDR agent 7.9.102-CE, Cortex XDR agent 8.1.2, Cortex XDR agent 8.2.1, and all later Cortex XDR agent versions.