Back

MEDIUM

Cortex XDR Agent: Local Privilege Escalation (PE) Vulnerability

Published Jun 12, 2024

Description

A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices enables a local user to execute programs with elevated privileges. However, execution does require the local user to successfully exploit a race condition, which makes this vulnerability difficult to exploit.

Affected products

Remediation

Vendor solution

This issue is fixed in Cortex XDR agent 7.9.102-CE, Cortex XDR agent 8.2.3, Cortex XDR agent 8.3.1, and all later Cortex XDR agent versions. This issue will not be addressed in Cortex XDR agent 8.1, which reached end-of-life (EoL) status on April 9, 2024.

Metrics

References (1)

Change history (3)
  1. CISA ADP
    • SSVC technical impact changed from total to partial
  2. CISA ADP
    • SSVC technical impact changed from partial to total
  3. CISA ADP
    • SSVC technical impact changed from total to partial
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner palo_alto
Published Jun 12, 2024
Updated Aug 1, 2024
Reserved Jun 12, 2024
CISA Vulnrichment
Updated Jun 12, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a