CVE-2024-5909
Cortex XDR Agent: Local Windows User Can Disable the Agent
Severity
Medium 6.8
CVSS 4.0
Exploited
Not listed
EPSS
0.004
33.7th percentile
Discovered by
Third party
Published by the vendor
Published
Jun 12, 2024
Assigned by palo_alto
Description
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.
Weakness: CWE-269
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | Cortex XDR | Endpoint / EDR | cna-assigner |
Vendor-reported affected versions (1)
- Palo Alto Networks · Cortex XDR Agent
Credit
Palo Alto Networks thanks Manuel Feifel of VUREX (InfoGuard AG) for discovering and reporting this issue.
Vendor remediation
This issue is fixed in Cortex XDR agent 7.9.102-CE, Cortex XDR agent 8.1.2, Cortex XDR agent 8.2.1, and all later Cortex XDR agent versions.