Show filters
21 Total Results
Displaying 1-10 of 21
Sort by:
Attacker Value
Unknown

CVE-2025-0112

Disclosure Date: February 20, 2025 (last updated February 20, 2025)
A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to disable the agent. This vulnerability can also be leveraged by malware to disable the Cortex XDR agent and then perform malicious activity.
0
Attacker Value
Unknown

CVE-2024-9469

Disclosure Date: October 09, 2024 (last updated October 16, 2024)
A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.
Attacker Value
Unknown

CVE-2024-8690

Disclosure Date: September 11, 2024 (last updated October 16, 2024)
A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows administrator privileges to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.
Attacker Value
Unknown

CVE-2024-5912

Disclosure Date: July 10, 2024 (last updated July 11, 2024)
An improper file signature check in Palo Alto Networks Cortex XDR agent may allow an attacker to bypass the Cortex XDR agent's executable blocking capabilities and run untrusted executables on the device. This issue can be leveraged to execute untrusted software without being detected or blocked.
0
Attacker Value
Unknown

CVE-2024-5909

Disclosure Date: June 12, 2024 (last updated August 08, 2024)
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.
Attacker Value
Unknown

CVE-2024-5907

Disclosure Date: June 12, 2024 (last updated August 08, 2024)
A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices enables a local user to execute programs with elevated privileges. However, execution does require the local user to successfully exploit a race condition, which makes this vulnerability difficult to exploit.
Attacker Value
Unknown

CVE-2024-5905

Disclosure Date: June 12, 2024 (last updated August 08, 2024)
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local low privileged Windows user to disrupt some functionality of the agent. However, they are not able to disrupt Cortex XDR agent protection mechanisms using this vulnerability.
Attacker Value
Unknown

CVE-2023-3280

Disclosure Date: September 13, 2023 (last updated October 08, 2023)
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user to disable the agent.
Attacker Value
Unknown

CVE-2023-0002

Disclosure Date: February 08, 2023 (last updated November 08, 2023)
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user to execute privileged cytool commands that disable or uninstall the agent.
Attacker Value
Unknown

CVE-2023-0001

Disclosure Date: February 08, 2023 (last updated November 08, 2023)
An information exposure vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local system administrator to disclose the admin password for the agent in cleartext, which bad actors can then use to execute privileged cytool commands that disable or uninstall the agent.