Cortex XDR Agent: Improper Control of User-Controlled File Leads to Local Privilege Escalation
CVE-2021-3042
Key Information:
- Vendor
- Palo Alto Networks
- Status
- Vendor
- CVE Published:
- 14 July 2021
Badges
Summary
A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables an authenticated local Windows user to execute programs with SYSTEM privileges. Exploiting this vulnerability requires the user to have file creation privilege in the Windows root directory (such as C:). This issue impacts: All versions of Cortex XDR agent 6.1 without content update 181 or a later version; All versions of Cortex XDR agent 7.2 without content update 181 or a later version; All versions of Cortex XDR agent 7.3 without content update 181 or a later version. Cortex XDR agent 5.0 versions are not impacted by this issue. Content updates are required to resolve this issue and are automatically applied for the agent.
Affected Version(s)
Cortex XDR Agent 5.0 all
Cortex XDR Agent Windows 6.1.* without content update 181 or later
Cortex XDR Agent Windows 7.2.* without content update 181 or later
References
CVSS V3.1
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved