CVE-2024-5909Improper Privilege Management in Palo Alto Networks Cortex XDR Agent

Severity
6.8MEDIUMNVD
EPSS
0.9%
top 24.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 12

Description

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Packages3 packages

NVDpaloaltonetworks/cortex_xdr_agent7.97.9.102+2
CVEListV5palo_alto_networks/cortex_xdr_agent8.2.08.2.1+2

🔴Vulnerability Details

2
CVEList
Cortex XDR Agent: Local Windows User Can Disable the Agent2024-06-12
GHSA
GHSA-26v6-wwwv-j4cc: A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to disa2024-06-12

📋Vendor Advisories

1
Palo Alto
Cortex XDR Agent: Local Windows User Can Disable the Agent2024-06-12
CVE-2024-5909 — Improper Privilege Management in Palo | cvebase