CVE-2024-5907

Cortex XDR Agent: Local Privilege Escalation (PE) Vulnerability

Severity
Medium 5.2
CVSS 4.0
Exploited
Not listed
EPSS
0.001
3.0th percentile
Discovered by
Third party
Vendor-published field
Published
Jun 12, 2024
Assigned by palo_alto

Description

A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices enables a local user to execute programs with elevated privileges. However, execution does require the local user to successfully exploit a race condition, which makes this vulnerability difficult to exploit.

Weakness: CWE-269

Affected products

Vendor Product Category Matched by
Palo Alto Networks Cortex XDR Endpoint / EDR cna-assigner
Vendor-reported products (1)
  • Palo Alto Networks · Cortex XDR Agent

Credit

Palo Alto Networks thanks Orange Cyberdefense Switzerland's Research Team for discovering and reporting this issue.

Vendor remediation

This issue is fixed in Cortex XDR agent 7.9.102-CE, Cortex XDR agent 8.2.3, Cortex XDR agent 8.3.1, and all later Cortex XDR agent versions. This issue will not be addressed in Cortex XDR agent 8.1, which reached end-of-life (EoL) status on April 9, 2024.

Something wrong here?