Local Privileged User Vulnerability Affects Cortex XDR Agent on Windows Devices
CVE-2024-5905

2LOW

Key Information:

Vendor
CVE Published:
12 June 2024

Badges

👾 Exploit Exists

What is CVE-2024-5905?

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local low privileged Windows user to disrupt some functionality of the agent. However, they are not able to disrupt Cortex XDR agent protection mechanisms using this vulnerability.

Affected Version(s)

Cortex XDR Agent Windows 7.9-CE < 7.9.102-CE

Cortex XDR Agent Windows 8.1.0 < 8.1.2

Cortex XDR Agent Windows 8.2.0 < 8.2.1

References

CVSS V4

Score:
2
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

.