Palo Alto Networks Security Advisories / CVE-2023-0002

CVE-2023-0002 Cortex XDR Agent: Product Disruption by Local Windows User

047910
Severity 5.5 · MEDIUM
Attack Vector LOCAL
Scope UNCHANGED
Attack Complexity LOW
Confidentiality Impact NONE
Privileges Required LOW
Integrity Impact NONE
User Interaction NONE
Availability Impact HIGH

Description

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user to execute privileged cytool commands that disable or uninstall the agent.

Product Status

VersionsAffectedUnaffected
Cortex XDR Agent 7.9Noneall
Cortex XDR Agent 7.8Noneall
Cortex XDR Agent 7.5< 7.5.101-CE on Windows>= 7.5.101-CE on Windows
Cortex XDR Agent 5.0< 5.0.12.22203 on Windows>= 5.0.12.22203 on Windows

Severity: MEDIUM

CVSSv3.1 Base Score: 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)

Weakness Type

CWE-693 Protection Mechanism Failure

Solution

This issue is fixed in Cortex XDR agent 5.0.12.22203, Cortex XDR agent 7.5.101-CE, and all later supported Cortex XDR agent versions.

Workarounds and Mitigations

There are no known workarounds for this issue.

Acknowledgments

Palo Alto Networks thanks Fernando Romero de la Morena and Robert McCallum (M42D) for discovering and reporting this issue.

Timeline

Initial publication
© 2024 Palo Alto Networks, Inc. All rights reserved.