CVE-2025-0121

Cortex XDR Agent: Local Windows User Can Crash the Agent

Severity
Medium 6.8
CVSS 4.0
Exploited
Not listed
EPSS
0.002
6.9th percentile
Discovered by
Third party
Vendor-published field
Published
Apr 11, 2025
Assigned by palo_alto

Description

A null pointer dereference vulnerability in the Palo Alto Networks Cortex® XDR agent on Windows devices allows a low-privileged local Windows user to crash the agent. Additionally, malware can use this vulnerability to perform malicious activity without Cortex XDR being able to detect it.

Weakness: CWE-476

Affected products

Vendor Product Category Matched by
Palo Alto Networks Cortex XDR Endpoint / EDR cna-assigner
Vendor-reported products (1)
  • Palo Alto Networks · Cortex XDR Agent

Credit

adcisseckilled

Vendor remediation

This issue is fixed in Cortex XDR Agent 8.6.1, Cortex XDR Agent 8.5.2, Cortex XDR Agent 8.3.101-CE HF, Cortex XDR Agent 7.9.103-CE HF, and all later Cortex XDR Agent versions.

Something wrong here?