CVE-2024-9469
Cortex XDR Agent: Local Windows User Can Disable the Agent
Severity
Medium 5.7
CVSS 4.0
Exploited
Not listed
EPSS
0.002
11.8th percentile
Discovered by
Third party
Vendor-published field
Published
Oct 9, 2024
Assigned by palo_alto
Description
A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.
Weakness: CWE-754
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | Cortex XDR | Endpoint / EDR | cna-assigner |
Vendor-reported products (1)
- Palo Alto Networks · Cortex XDR Agent
Credit
Orange Cyberdefense Switzerland's Research Team
Vendor remediation
This issue is fixed in Cortex XDR Agent 7.9.102-CE, Cortex XDR Agent 8.3.1, Cortex XDR Agent 8.4.1, and all later Cortex XDR Agent versions.