A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices enables a local user to execute programs with elevated privileges. However, execution does require the local user to successfully exploit a race condition, which makes this vulnerability difficult to exploit.

Subscriptions

Vendors Products
Paloaltonetworks Subscribe
Cortex Xdr Agent Subscribe

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-47039 A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices enables a local user to execute programs with elevated privileges. However, execution does require the local user to successfully exploit a race condition, which makes this vulnerability difficult to exploit.
Fixes

Solution

This issue is fixed in Cortex XDR agent 7.9.102-CE, Cortex XDR agent 8.2.3, Cortex XDR agent 8.3.1, and all later Cortex XDR agent versions. This issue will not be addressed in Cortex XDR agent 8.1, which reached end-of-life (EoL) status on April 9, 2024.


Workaround

No workaround given by the vendor.

History

Wed, 07 Aug 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Paloaltonetworks
Paloaltonetworks cortex Xdr Agent
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:*:*:*:*:*:*:*:*
cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:*:*:*:*:critical_environment:*:*:*
Vendors & Products Paloaltonetworks
Paloaltonetworks cortex Xdr Agent
Metrics cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: palo_alto

Published:

Updated: 2024-08-01T21:25:03.047Z

Reserved: 2024-06-12T15:27:55.262Z

Link: CVE-2024-5907

cve-icon Vulnrichment

Updated: 2024-08-01T21:25:03.047Z

cve-icon NVD

Status : Modified

Published: 2024-06-12T17:15:53.127

Modified: 2024-11-21T09:48:33.463

Link: CVE-2024-5907

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses