QID 376469

Date Published: 2022-03-15

QID 376469: Palo Alto Networks Cortex XDR Agent Privilege Escalation (PE) Vulnerability (CPATR-13405, CPATR-9287)

An Uncontrolled Search Path Element Leads to Local Privilege Escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent

Affected versions:
Cortex XDR agent 5.0 versions earlier than Cortex XDR agent 5.0.12;
Cortex XDR agent 6.1 versions earlier than Cortex XDR agent 6.1.9;

QID Detection Logic (Authenticated) :
This checks for vulnerable version of CyveraConsole.exe file.

Successful exploitation enables an authenticated local user to execute programs with elevated privileges.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Vendor has released updates to fix the issue. Please refer to vendor advisory CVE-2022-0015 for more information.
    Vendor References

    CVEs related to QID 376469

    Software Advisories
    Advisory ID Software Component Link
    CVE-2022-0015 URL Logo security.paloaltonetworks.com/CVE-2022-0015