<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Palo Alto Networks Cortex XDR agent</title>
  <link>https://cvedaily.com/pages/tags/cortex-xdr.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/cortex-xdr.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Palo Alto Networks Cortex XDR agent</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:56 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-0232 – A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0232</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0232</guid>
    <pubDate>Mon, 13 Apr 2026 08:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0232</strong></p>
  <p>A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent. This issue may be leveraged by malware to perform malicious activity without detection.</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-15</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0232">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0231 – An information disclosure vulnerability in Palo Alto Networks Cortex XDR® Broker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0231</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0231</guid>
    <pubDate>Wed, 11 Mar 2026 18:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0231</strong></p>
  <p>An information disclosure vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to obtain and modify sensitive information by triggering live terminal session via Cortex UI and modifying any configuration setting.  The attacker must have network access to the Broker VM to exploit this issue.</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-497</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0231">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0230 – A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0230</guid>
    <pubDate>Wed, 11 Mar 2026 18:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0230</strong></p>
  <p>A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on macOS allows a local administrator to disable the agent. This issue could be leveraged by malware to perform malicious activity without detection.</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-4234 – A problem with the Palo Alto Networks Cortex XDR Microsoft 365 Defender Pack can...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4234</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4234</guid>
    <pubDate>Fri, 12 Sep 2025 18:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-4234</strong></p>
  <p>A problem with the Palo Alto Networks Cortex XDR Microsoft 365 Defender Pack can result in exposure of user credentials in application logs. Normally, these application logs are only viewable by local users and are included when generating logs for troubleshooting purposes. This means that these credentials are exposed to recipients of the application logs.</p>
  <p><strong>CVSS:</strong> 2.4 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4234">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-2184 – A credential management flaw in Palo Alto Networks Cortex XDR® Broker VM causes ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2184</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2184</guid>
    <pubDate>Wed, 13 Aug 2025 17:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-2184</strong></p>
  <p>A credential management flaw in Palo Alto Networks Cortex XDR® Broker VM causes different Broker VM images to share identical default credentials for internal services. Users knowing these default credentials could access internal services on other Broker VM installations.  The attacker must have network access to the Broker VM to exploit this issue.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2184">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-0134 – A code injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0134</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0134</guid>
    <pubDate>Wed, 14 May 2025 19:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-0134</strong></p>
  <p>A code injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute arbitrary code with root privileges on the host operating system running Broker VM.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0134">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-0132 – A missing authentication vulnerability in Palo Alto Networks Cortex XDR® Broker ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0132</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0132</guid>
    <pubDate>Wed, 14 May 2025 19:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-0132</strong></p>
  <p>A missing authentication vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an unauthenticated user to disable certain internal services on the Broker VM.   The attacker must have network access to the Broker VM to exploit this issue.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0132">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-0119 – A command injection vulnerability in the Palo Alto Networks Cortex XDR® Broker V...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0119</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0119</guid>
    <pubDate>Fri, 11 Apr 2025 18:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-0119</strong></p>
  <p>A command injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute arbitrary OS commands with root privileges on the host operating system running Broker VM.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0119">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-0121 – A null pointer dereference vulnerability in the Palo Alto Networks Cortex® XDR a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0121</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0121</guid>
    <pubDate>Fri, 11 Apr 2025 02:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-0121</strong></p>
  <p>A null pointer dereference vulnerability in the Palo Alto Networks Cortex® XDR agent on Windows devices allows a low-privileged local Windows user to crash the agent. Additionally, malware can use this vulnerability to perform malicious activity without Cortex XDR being able to detect it.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0121">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-0112 – A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0112</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0112</guid>
    <pubDate>Thu, 20 Feb 2025 00:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-0112</strong></p>
  <p>A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to disable the agent. This vulnerability can also be leveraged by malware to disable the Cortex XDR agent and then perform malicious activity.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0112">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-0113 – A problem with the network isolation mechanism of the Palo Alto Networks Cortex ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0113</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0113</guid>
    <pubDate>Wed, 12 Feb 2025 21:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-0113</strong></p>
  <p>A problem with the network isolation mechanism of the Palo Alto Networks Cortex XDR Broker VM allows attackers unauthorized access to Docker containers from the host network used by Broker VM. This may allow access to read files sent for analysis and logs transmitted by the Cortex XDR Agent to the Cortex XDR server.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-424</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0113">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-9469 – A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-9469</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-9469</guid>
    <pubDate>Wed, 09 Oct 2024 17:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-9469</strong></p>
  <p>A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9469">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-8690 – A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8690</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8690</guid>
    <pubDate>Wed, 11 Sep 2024 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-8690</strong></p>
  <p>A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows administrator privileges to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-440</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8690">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-5912 – An improper file signature check in Palo Alto Networks Cortex XDR agent may allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5912</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5912</guid>
    <pubDate>Wed, 10 Jul 2024 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-5912</strong></p>
  <p>An improper file signature check in Palo Alto Networks Cortex XDR agent may allow an attacker to bypass the Cortex XDR agent's executable blocking capabilities and run untrusted executables on the device. This issue can be leveraged to execute untrusted software without being detected or blocked.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5912">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-5909 – A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5909</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5909</guid>
    <pubDate>Wed, 12 Jun 2024 17:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-5909</strong></p>
  <p>A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5909">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-5907 – A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5907</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5907</guid>
    <pubDate>Wed, 12 Jun 2024 17:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-5907</strong></p>
  <p>A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices enables a local user to execute programs with elevated privileges. However, execution does require the local user to successfully exploit a race condition, which makes this vulnerability difficult to exploit.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5907">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-5905 – A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5905</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5905</guid>
    <pubDate>Wed, 12 Jun 2024 17:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-5905</strong></p>
  <p>A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local low privileged Windows user to disrupt some functionality of the agent. However, they are not able to disrupt Cortex XDR agent protection mechanisms using this vulnerability.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-346</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5905">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-3280 – A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-3280</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-3280</guid>
    <pubDate>Wed, 13 Sep 2023 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-3280</strong></p>
  <p>A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user to disable the agent.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-755</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3280">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-0002 – A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0002</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0002</guid>
    <pubDate>Wed, 08 Feb 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-0002</strong></p>
  <p>A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user to execute privileged cytool commands that disable or uninstall the agent.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0002">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-0001 – An information exposure vulnerability in the Palo Alto Networks Cortex XDR agent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0001</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0001</guid>
    <pubDate>Wed, 08 Feb 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-0001</strong></p>
  <p>An information exposure vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local system administrator to disclose the admin password for the agent in cleartext, which bad actors can then use to execute privileged cytool commands that disable or uninstall the agent.</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0001">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-0029 – An improper link resolution vulnerability in the Palo Alto Networks Cortex XDR a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-0029</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-0029</guid>
    <pubDate>Wed, 14 Sep 2022 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-0029</strong></p>
  <p>An improper link resolution vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local attacker to read files on the system with elevated privileges when generating a tech support file.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0029">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-0026 – A local privilege escalation (PE) vulnerability exists in Palo Alto Networks Cor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-0026</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-0026</guid>
    <pubDate>Wed, 11 May 2022 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-0026</strong></p>
  <p>A local privilege escalation (PE) vulnerability exists in Palo Alto Networks Cortex XDR agent software on Windows that enables an authenticated local user with file creation privilege in the Windows root directory (such as C:\) to execute a program with elevated privileges. This issue impacts all versions of Cortex XDR agent without content update 330 or a later content update version.</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-282</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0026">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-0025 – A local privilege escalation (PE) vulnerability exists in Palo Alto Networks Cor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-0025</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-0025</guid>
    <pubDate>Wed, 11 May 2022 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-0025</strong></p>
  <p>A local privilege escalation (PE) vulnerability exists in Palo Alto Networks Cortex XDR agent software on Windows that enables an authenticated local user with file creation privilege in the Windows root directory (such as C:\) to execute a program with elevated privileges. This issue impacts: All versions of the Cortex XDR agent when upgrading to Cortex XDR agent 7.7.0 on Windows; Cortex XDR age…</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0025">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-0015 – A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-0015</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-0015</guid>
    <pubDate>Wed, 12 Jan 2022 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-0015</strong></p>
  <p>A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables an authenticated local user to execute programs with elevated privileges. This issue impacts: Cortex XDR agent 5.0 versions earlier than Cortex XDR agent 5.0.12; Cortex XDR agent 6.1 versions earlier than Cortex XDR agent 6.1.9.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0015">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-0014 – An untrusted search path vulnerability exists in the Palo Alto Networks Cortex X...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-0014</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-0014</guid>
    <pubDate>Wed, 12 Jan 2022 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-0014</strong></p>
  <p>An untrusted search path vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables a local attacker with file creation privilege in the Windows root directory (such as C:\) to store a program that can then be unintentionally executed by another local user when that user utilizes a Live Terminal session. This issue impacts: Cortex XDR agent 5.0 versions earlier than Cortex XDR a…</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0014">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-0013 – A file information exposure vulnerability exists in the Palo Alto Networks Corte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-0013</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-0013</guid>
    <pubDate>Wed, 12 Jan 2022 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-0013</strong></p>
  <p>A file information exposure vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables a local attacker to read the contents of arbitrary files on the system with elevated privileges when generating a support file. This issue impacts: Cortex XDR agent 5.0 versions earlier than Cortex XDR agent 5.0.12; Cortex XDR agent 6.1 versions earlier than Cortex XDR agent 6.1.9; Cortex XDR…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-538</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0013">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-0012 – An improper link resolution before file access vulnerability exists in the Palo ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-0012</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-0012</guid>
    <pubDate>Wed, 12 Jan 2022 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-0012</strong></p>
  <p>An improper link resolution before file access vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables a local user to delete arbitrary system files and impact the system integrity or cause a denial of service condition. This issue impacts: Cortex XDR agent 5.0 versions earlier than Cortex XDR agent 5.0.12; Cortex XDR agent 6.1 versions earlier than Corte…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0012">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3042 – A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3042</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3042</guid>
    <pubDate>Thu, 15 Jul 2021 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3042</strong></p>
  <p>A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables an authenticated local Windows user to execute programs with SYSTEM privileges. Exploiting this vulnerability requires the user to have file creation privilege in the Windows root directory (such as C:\). This issue impacts: All versions of Cortex XDR agent 6.1 witho…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3042">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3041 – A local privilege escalation vulnerability exists in the Palo Alto Networks Cort...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3041</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3041</guid>
    <pubDate>Thu, 10 Jun 2021 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3041</strong></p>
  <p>A local privilege escalation vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables an authenticated local Windows user to execute programs with SYSTEM privileges. This requires the user to have the privilege to create files in the Windows root directory or to manipulate key registry values. This issue impacts: Cortex XDR agent 5.0 versions earlier than…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3041">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-2049 – A local privilege escalation vulnerability exists in Palo Alto Networks Cortex X...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-2049</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-2049</guid>
    <pubDate>Wed, 09 Dec 2020 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-2049</strong></p>
  <p>A local privilege escalation vulnerability exists in Palo Alto Networks Cortex XDR Agent on the Windows platform that allows an authenticated local Windows user to execute programs with SYSTEM privileges. This requires the user to have the privilege to create files in the Windows root directory. This issue impacts: All versions of Cortex XDR Agent 7.1 with content update 149 and earlier versions;…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-2049">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-2020 – An improper handling of exceptional conditions vulnerability in Cortex XDR Agent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-2020</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-2020</guid>
    <pubDate>Wed, 09 Dec 2020 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-2020</strong></p>
  <p>An improper handling of exceptional conditions vulnerability in Cortex XDR Agent allows a local authenticated Windows user to create files in the software's internal program directory that prevents the Cortex XDR Agent from starting. The exceptional condition is persistent and prevents Cortex XDR Agent from starting when the software or machine is restarted. This issue impacts: Cortex XDR Agent 5…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-755</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-2020">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-1991 – An insecure temporary file vulnerability in Palo Alto Networks Traps allows a lo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-1991</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-1991</guid>
    <pubDate>Wed, 08 Apr 2020 19:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-1991</strong></p>
  <p>An insecure temporary file vulnerability in Palo Alto Networks Traps allows a local authenticated Windows user to escalate privileges or overwrite system files. This issue affects Palo Alto Networks Traps 5.0 versions before 5.0.8; 6.1 versions before 6.1.4 on Windows. This issue does not affect Cortex XDR 7.0. This issue does not affect Traps for Linux or MacOS.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-377</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-1991">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
