Impact
A local attacker who already holds administrator privileges on a Windows system can bypass the Prisma Access Agent’s anti‑tamper protection, allowing that attacker to access processes and files that are normally protected by the agent. The flaw is a classic example of improper protection of essential data (CWE‑693).
Affected Systems
The vulnerability affects Palo Alto Networks Prisma Access Agent on Windows versions 24.0 through 26.2.2. Versions on macOS, Linux, iOS, Android, and Chrome OS are not impacted.
Risk and Exploitability
The CVSS score of 5.6 indicates a moderate severity. Because the exploit requires local administrator rights and there are no public exploits documented, the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalogue. The attack vector is local, so only users who can already gain administrative access to a Windows machine can leverage this weakness to obtain further unauthorized access to protected processes or files.
OpenCVE Enrichment