Null Pointer Dereference in Palo Alto Networks Cortex XDR Agent on Windows Systems
CVE-2025-0121
Key Information:
- Vendor
Palo Alto Networks
- Status
- Vendor
- CVE Published:
- 11 April 2025
Badges
What is CVE-2025-0121?
A null pointer dereference vulnerability exists in the Palo Alto Networks Cortex® XDR agent on Windows systems. This flaw allows low-privileged local users to crash the Cortex XDR agent, potentially leading to disruption of security monitoring. Furthermore, malicious software may exploit this vulnerability to carry out unauthorized activities without being detected by the Cortex XDR protection mechanisms.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cortex XDR Agent Windows 8.6.0 < 8.6.1
Cortex XDR Agent Windows 8.5.0 < 8.5.2
Cortex XDR Agent Windows 8.3-CE < 8.3.101-CE HF
References
CVSS V4
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved