CVE-2020-2049: Cortex XDR Agent: Improper control of loaded DLL leads to local privilege escalation
A local privilege escalation vulnerability exists in Palo Alto Networks Cortex XDR Agent on the Windows platform that allows an authenticated local Windows user to execute programs with SYSTEM privileges. This requires the user to have the privilege to create files in the Windows root directory. This issue impacts: All versions of Cortex XDR Agent 7.1 with content update 149 and earlier versions; All versions of Cortex XDR Agent 7.2 with content update 149 and earlier versions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2020-2049?
CVE-2020-2049 is classified with a high severity level due to its potential for local privilege escalation.
How do I fix CVE-2020-2049?
To mitigate CVE-2020-2049, users should upgrade the Palo Alto Networks Cortex XDR Agent to a patched version beyond 7.2.2.
Who is affected by CVE-2020-2049?
CVE-2020-2049 affects authenticated local Windows users running specific versions of the Palo Alto Networks Cortex XDR Agent.
Can CVE-2020-2049 be exploited remotely?
No, CVE-2020-2049 requires an authenticated local user access to exploit the vulnerability.
What systems are vulnerable to CVE-2020-2049?
The vulnerability CVE-2020-2049 primarily affects Windows systems with Palo Alto Networks Cortex XDR Agent versions 7.1.1 to 7.2.2.