A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47041 | A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity. |
Fixes
Solution
This issue is fixed in Cortex XDR agent 7.9.102-CE, Cortex XDR agent 8.1.2, Cortex XDR agent 8.2.1, and all later Cortex XDR agent versions.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://security.paloaltonetworks.com/CVE-2024-5909 |
|
History
Wed, 07 Aug 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Paloaltonetworks
Paloaltonetworks cortex Xdr Agent |
|
| CPEs | cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:*:*:*:*:*:windows:*:* cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:*:*:*:*:critical_environment:windows:*:* |
|
| Vendors & Products |
Paloaltonetworks
Paloaltonetworks cortex Xdr Agent |
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: palo_alto
Published:
Updated: 2024-08-01T21:25:03.192Z
Reserved: 2024-06-12T15:27:55.683Z
Link: CVE-2024-5909
Updated: 2024-08-01T21:25:03.192Z
Status : Modified
Published: 2024-06-12T17:15:53.370
Modified: 2024-11-21T09:48:33.737
Link: CVE-2024-5909
No data.
OpenCVE Enrichment
No data.
EUVD