QID 376469
Date Published: 2022-03-15
QID 376469: Palo Alto Networks Cortex XDR Agent Privilege Escalation (PE) Vulnerability (CPATR-13405, CPATR-9287)
An Uncontrolled Search Path Element Leads to Local Privilege Escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent
Affected versions:
Cortex XDR agent 5.0 versions earlier than Cortex XDR agent 5.0.12;
Cortex XDR agent 6.1 versions earlier than Cortex XDR agent 6.1.9;
QID Detection Logic (Authenticated) :
This checks for vulnerable version of CyveraConsole.exe file.
Successful exploitation enables an authenticated local user to execute programs with elevated privileges.
Solution
Vendor has released updates to fix the issue. Please refer to vendor advisory CVE-2022-0015 for more information.
Vendor References
- CVE-2022-0015 -
security.paloaltonetworks.com/CVE-2022-0015
CVEs related to QID 376469
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2022-0015 |
|