Back

MEDIUM

Cortex XDR Agent: Improper Link Resolution Vulnerability When Generating a Tech Support File

Published Sep 14, 2022

Description

An improper link resolution vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local attacker to read files on the system with elevated privileges when generating a tech support file.

Affected products

Remediation

Vendor solution

This issue is fixed in Cortex XDR agent 5.0.12-hotfix update, Cortex XDR agent 7.5.101-CE, Cortex XDR agent 7.7.3, and all later versions of the Cortex XDR agent.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner palo_alto
Published Sep 14, 2022
Updated Jun 4, 2025
Reserved Dec 28, 2021
CISA Vulnrichment
Updated Jun 4, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a