CVE-2023-0002 Cortex XDR Agent: Product Disruption by Local Windows User
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user to execute privileged cytool commands that disable or uninstall the agent.
|Cortex XDR Agent 7.9||None||all|
|Cortex XDR Agent 7.8||None||all|
|Cortex XDR Agent 7.5||< 7.5.101-CE on Windows||>= 7.5.101-CE on Windows|
|Cortex XDR Agent 5.0||< 126.96.36.19903 on Windows||>= 188.8.131.5203 on Windows|
CVSSv3.1 Base Score:5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
This issue is fixed in Cortex XDR agent 184.108.40.20603, Cortex XDR agent 7.5.101-CE, and all later supported Cortex XDR agent versions.
Workarounds and Mitigations
There are no known workarounds for this issue.