CVE-2020-2049
Summary
| CVE | CVE-2020-2049 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-09 18:15:00 UTC |
| Updated | 2020-12-16 18:56:00 UTC |
| Description | A local privilege escalation vulnerability exists in Palo Alto Networks Cortex XDR Agent on the Windows platform that allows an authenticated local Windows user to execute programs with SYSTEM privileges. This requires the user to have the privilege to create files in the Windows root directory. This issue impacts: All versions of Cortex XDR Agent 7.1 with content update 149 and earlier versions; All versions of Cortex XDR Agent 7.2 with content update 149 and earlier versions. |
Risk And Classification
Problem Types: CWE-427
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Microsoft | Windows | - | All | All | All |
| Operating System | Microsoft | Windows | - | All | All | All |
| Application | Paloaltonetworks | Cortex Xdr Agent | 7.1 | - | All | All |
| Application | Paloaltonetworks | Cortex Xdr Agent | 7.1 | content_update149 | All | All |
| Application | Paloaltonetworks | Cortex Xdr Agent | 7.2 | - | All | All |
| Application | Paloaltonetworks | Cortex Xdr Agent | 7.2 | content_update149 | All | All |
| Application | Paloaltonetworks | Cortex Xdr Agent | 7.1 | - | All | All |
| Application | Paloaltonetworks | Cortex Xdr Agent | 7.1 | content_update149 | All | All |
| Application | Paloaltonetworks | Cortex Xdr Agent | 7.2 | - | All | All |
| Application | Paloaltonetworks | Cortex Xdr Agent | 7.2 | content_update149 | All | All |
| Application | Paloaltonetworks | Cortex Xdr Agent | All | All | All | All |
| Application | Paloaltonetworks | Cortex Xdr Agent | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2020-2049 Cortex XDR Agent: Improper control of loaded DLL leads to local privilege escalation | CONFIRM | security.paloaltonetworks.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Palo Alto Networks thanks Chris Au of PwC Hong Kong - Darklab and Xavier DANEST of Decathlon for discovering and reporting this issue.
There are currently no legacy QID mappings associated with this CVE.