An improper link resolution vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local attacker to read files on the system with elevated privileges when generating a tech support file.
Fixes

Solution

This issue is fixed in Cortex XDR agent 5.0.12-hotfix update, Cortex XDR agent 7.5.101-CE, Cortex XDR agent 7.7.3, and all later versions of the Cortex XDR agent.


Workaround

No workaround given by the vendor.

History

Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00056}

epss

{'score': 0.00059}


Wed, 04 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: palo_alto

Published:

Updated: 2025-06-04T15:08:32.763Z

Reserved: 2021-12-28T00:00:00.000Z

Link: CVE-2022-0029

cve-icon Vulnrichment

Updated: 2024-08-02T23:18:41.370Z

cve-icon NVD

Status : Modified

Published: 2022-09-14T17:15:10.110

Modified: 2024-11-21T06:37:51.280

Link: CVE-2022-0029

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.