CVE-2023-0002 Cortex XDR Agent: Product Disruption by Local Windows User
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user to execute privileged cytool commands that disable or uninstall the agent.
|Cortex XDR Agent 7.9||None||all|
|Cortex XDR Agent 7.8||None||all|
|Cortex XDR Agent 7.5||< 7.5.101-CE on Windows||>= 7.5.101-CE on Windows|
|Cortex XDR Agent 5.0||< 220.127.116.1103 on Windows||>= 18.104.22.16803 on Windows|
CVSSv3.1 Base Score: 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
This issue is fixed in Cortex XDR agent 22.214.171.12403, Cortex XDR agent 7.5.101-CE, and all later supported Cortex XDR agent versions.
Workarounds and Mitigations
There are no known workarounds for this issue.