<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Palo Alto Networks Cortex XDR agent (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/cortex-xdr.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/cortex-xdr-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Palo Alto Networks Cortex XDR agent (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:56 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2024-5907 – A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5907</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5907</guid>
    <pubDate>Wed, 12 Jun 2024 17:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-5907</strong></p>
  <p>A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices enables a local user to execute programs with elevated privileges. However, execution does require the local user to successfully exploit a race condition, which makes this vulnerability difficult to exploit.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5907">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-0015 – A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-0015</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-0015</guid>
    <pubDate>Wed, 12 Jan 2022 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-0015</strong></p>
  <p>A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables an authenticated local user to execute programs with elevated privileges. This issue impacts: Cortex XDR agent 5.0 versions earlier than Cortex XDR agent 5.0.12; Cortex XDR agent 6.1 versions earlier than Cortex XDR agent 6.1.9.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0015">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3042 – A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3042</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3042</guid>
    <pubDate>Thu, 15 Jul 2021 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3042</strong></p>
  <p>A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables an authenticated local Windows user to execute programs with SYSTEM privileges. Exploiting this vulnerability requires the user to have file creation privilege in the Windows root directory (such as C:\). This issue impacts: All versions of Cortex XDR agent 6.1 witho…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3042">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3041 – A local privilege escalation vulnerability exists in the Palo Alto Networks Cort...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3041</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3041</guid>
    <pubDate>Thu, 10 Jun 2021 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3041</strong></p>
  <p>A local privilege escalation vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables an authenticated local Windows user to execute programs with SYSTEM privileges. This requires the user to have the privilege to create files in the Windows root directory or to manipulate key registry values. This issue impacts: Cortex XDR agent 5.0 versions earlier than…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3041">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-2049 – A local privilege escalation vulnerability exists in Palo Alto Networks Cortex X...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-2049</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-2049</guid>
    <pubDate>Wed, 09 Dec 2020 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-2049</strong></p>
  <p>A local privilege escalation vulnerability exists in Palo Alto Networks Cortex XDR Agent on the Windows platform that allows an authenticated local Windows user to execute programs with SYSTEM privileges. This requires the user to have the privilege to create files in the Windows root directory. This issue impacts: All versions of Cortex XDR Agent 7.1 with content update 149 and earlier versions;…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-2049">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-1991 – An insecure temporary file vulnerability in Palo Alto Networks Traps allows a lo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-1991</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-1991</guid>
    <pubDate>Wed, 08 Apr 2020 19:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-1991</strong></p>
  <p>An insecure temporary file vulnerability in Palo Alto Networks Traps allows a local authenticated Windows user to escalate privileges or overwrite system files. This issue affects Palo Alto Networks Traps 5.0 versions before 5.0.8; 6.1 versions before 6.1.4 on Windows. This issue does not affect Cortex XDR 7.0. This issue does not affect Traps for Linux or MacOS.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-377</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-1991">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
