A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.
2024-10-09T17:15:20.770
2024-10-15T18:38:25.647
Analyzed
CVSSv3.1: 5.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | paloaltonetworks | cortex_xdr_agent | < 7.9.102 | Yes |
Application | paloaltonetworks | cortex_xdr_agent | 8.3.0 | Yes |
Application | paloaltonetworks | cortex_xdr_agent | 8.4.0 | Yes |
Operating System | microsoft | windows | - | No |