CVE-2025-0121
Cortex XDR Agent: Local Windows User Can Crash the Agent
Severity
Medium 6.8
CVSS 4.0
Exploited
Not listed
EPSS
0.002
6.9th percentile
Discovered by
Third party
Vendor-published field
Published
Apr 11, 2025
Assigned by palo_alto
Description
A null pointer dereference vulnerability in the Palo Alto Networks Cortex® XDR agent on Windows devices allows a low-privileged local Windows user to crash the agent. Additionally, malware can use this vulnerability to perform malicious activity without Cortex XDR being able to detect it.
Weakness: CWE-476
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | Cortex XDR | Endpoint / EDR | cna-assigner |
Vendor-reported products (1)
- Palo Alto Networks · Cortex XDR Agent
Credit
adcisseckilled
Vendor remediation
This issue is fixed in Cortex XDR Agent 8.6.1, Cortex XDR Agent 8.5.2, Cortex XDR Agent 8.3.101-CE HF, Cortex XDR Agent 7.9.103-CE HF, and all later Cortex XDR Agent versions.