PT-2022-12951 · Palo Alto Networks · Cortex Xdr Agent

Robert Mccallum

·

Published

2022-01-12

·

Updated

2022-01-19

·

CVE-2022-0014

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cortex XDR agent versions prior to 5.0.12 Cortex XDR agent versions prior to 6.1.9 Cortex XDR agent versions prior to 7.2.4 Cortex XDR agent versions prior to 7.3.2
Description An untrusted search path issue exists in the Palo Alto Networks Cortex XDR agent, allowing a local attacker with file creation privilege in the Windows root directory to store a program that can then be unintentionally executed by another local user when that user utilizes a Live Terminal session.
Recommendations For versions prior to 5.0.12, update to version 5.0.12 or later. For versions prior to 6.1.9, update to version 6.1.9 or later. For versions prior to 7.2.4, update to version 7.2.4 or later. For versions prior to 7.3.2, update to version 7.3.2 or later.

Fix

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-0014

Affected Products

Cortex Xdr Agent