PT-2024-4210 · Palo Alto Networks · Palo Alto Networks Cortex Xdr Agent

Manuel Feifel

·

Published

2024-06-12

·

Updated

2025-10-19

·

CVE-2024-5909

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/AU:N/R:U/V:D/RE:M/U:Amber
Name of the Vulnerable Software and Affected Versions Palo Alto Networks Cortex XDR Agent (affected versions not specified)
Description An issue exists in the Palo Alto Networks Cortex XDR Agent related to insecure privilege management on Windows devices. A low-privileged local Windows user can disable the agent. This could be exploited by malware to deactivate the Cortex XDR agent and then carry out malicious activities.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2024-04696
CVE-2024-5909

Affected Products

Palo Alto Networks Cortex Xdr Agent