PT-2025-7456 · Palo Alto Networks · Palo Alto Networks Cortex Xdr Agent

Eldar Aharoni

·

Published

2025-02-12

·

Updated

2025-02-20

·

CVE-2025-0112

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:D/RE:X/U:Amber
Name of the Vulnerable Software and Affected Versions Palo Alto Networks Cortex XDR agent (affected versions not specified)
Description A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to disable the agent. This issue can also be leveraged by malware to disable the Cortex XDR agent and then perform malicious activity.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Improper Check for Exceptional Conditions

Weakness Enumeration

Related Identifiers

BDU:2025-08773
CVE-2025-0112

Affected Products

Palo Alto Networks Cortex Xdr Agent