A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices enables a local user to execute programs with elevated privileges. However, execution does require the local user to successfully exploit a race condition, which makes this vulnerability difficult to exploit.
History

Wed, 07 Aug 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Paloaltonetworks
Paloaltonetworks cortex Xdr Agent
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:*:*:*:*:*:*:*:*
cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:*:*:*:*:critical_environment:*:*:*
Vendors & Products Paloaltonetworks
Paloaltonetworks cortex Xdr Agent
Metrics cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: palo_alto

Published: 2024-06-12T16:26:39.742Z

Updated: 2024-08-01T21:25:03.047Z

Reserved: 2024-06-12T15:27:55.262Z

Link: CVE-2024-5907

cve-icon Vulnrichment

Updated: 2024-08-01T21:25:03.047Z

cve-icon NVD

Status : Analyzed

Published: 2024-06-12T17:15:53.127

Modified: 2024-08-07T16:59:29.527

Link: CVE-2024-5907

cve-icon Redhat

No data.