CVE-2023-0002 Cortex XDR Agent: Product Disruption by Local Windows User
Attack Vector LOCAL
Attack Complexity LOW
Confidentiality Impact NONE
Privileges Required LOW
Integrity Impact NONE
User Interaction NONE
Availability Impact HIGH
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user to execute privileged cytool commands that disable or uninstall the agent.
|Cortex XDR Agent 7.9||None||all|
|Cortex XDR Agent 7.8||None||all|
|Cortex XDR Agent 7.5||< 7.5.101-CE on Windows||>= 7.5.101-CE on Windows|
|Cortex XDR Agent 5.0||< 220.127.116.1103 on Windows||>= 18.104.22.16803 on Windows|
CVSSv3.1 Base Score:5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
CWE-693 Protection Mechanism Failure
This issue is fixed in Cortex XDR agent 22.214.171.12403, Cortex XDR agent 7.5.101-CE, and all later supported Cortex XDR agent versions.
Workarounds and Mitigations
There are no known workarounds for this issue.
Palo Alto Networks thanks Fernando Romero de la Morena and Robert McCallum (M42D) for discovering and reporting this issue.