Palo Alto Networks Security Advisories / CVE-2023-0002

CVE-2023-0002 Cortex XDR Agent: Product Disruption by Local Windows User

Severity 5.5 · MEDIUM
Attack Vector LOCAL
Attack Complexity LOW
Confidentiality Impact NONE
Privileges Required LOW
Integrity Impact NONE
User Interaction NONE
Availability Impact HIGH


A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user to execute privileged cytool commands that disable or uninstall the agent.

Product Status

Cortex XDR Agent 7.9NoneAll
Cortex XDR Agent 7.8NoneAll
Cortex XDR Agent 7.5< 7.5.101-CE on Windows>= 7.5.101-CE on Windows
Cortex XDR Agent 5.0< on Windows>= on Windows

Severity: MEDIUM

CVSSv3.1 Base Score: 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)

Weakness Type

CWE-693 Protection Mechanism Failure


This issue is fixed in Cortex XDR agent, Cortex XDR agent 7.5.101-CE, and all later supported Cortex XDR agent versions.

Workarounds and Mitigations

There are no known workarounds for this issue.


Palo Alto Networks thanks Fernando Romero de la Morena and Robert McCallum (M42D) for discovering and reporting this issue.


Initial publication
© 2024 Palo Alto Networks, Inc. All rights reserved.