A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows administrator privileges to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.
History

Tue, 15 Oct 2024 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft
Microsoft windows
CPEs cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:7.9.102-ce:*:*:*:*:windows:*:* cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:7.9.102:*:*:*:critical_environment:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows

Thu, 03 Oct 2024 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Paloaltonetworks
Paloaltonetworks cortex Xdr Agent
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:7.9.102-ce:*:*:*:*:windows:*:*
Vendors & Products Paloaltonetworks
Paloaltonetworks cortex Xdr Agent
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}


Wed, 11 Sep 2024 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 11 Sep 2024 17:00:00 +0000

Type Values Removed Values Added
Description A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows administrator privileges to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.
Title Cortex XDR Agent: Local Windows Administrator Can Disable the Agent
Weaknesses CWE-440
References
Metrics cvssV4_0

{'score': 5.6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:L/AU:N/R:U/V:D/RE:M/U:Amber'}


cve-icon MITRE

Status: PUBLISHED

Assigner: palo_alto

Published: 2024-09-11T16:42:39.974Z

Updated: 2024-09-11T18:24:05.107Z

Reserved: 2024-09-11T08:21:15.662Z

Link: CVE-2024-8690

cve-icon Vulnrichment

Updated: 2024-09-11T18:23:56.959Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-11T17:15:14.487

Modified: 2024-10-15T18:38:32.260

Link: CVE-2024-8690

cve-icon Redhat

No data.