First published: Wed Jan 12 2022(Updated: )
An improper link resolution before file access vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables a local user to delete arbitrary system files and impact the system integrity or cause a denial of service condition. This issue impacts: Cortex XDR agent 5.0 versions earlier than Cortex XDR agent 5.0.12; Cortex XDR agent 6.1 versions earlier than Cortex XDR agent 6.1.9; Cortex XDR agent 7.2 versions earlier than Cortex XDR agent 7.2.4; Cortex XDR agent 7.3 versions earlier than Cortex XDR agent 7.3.2.
Credit: psirt@paloaltonetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Paloaltonetworks Cortex Xdr Agent | >=5.0<5.0.12 | |
Paloaltonetworks Cortex Xdr Agent | >=6.1<6.1.9 | |
Paloaltonetworks Cortex Xdr Agent | >=7.2<7.2.4 | |
Paloaltonetworks Cortex Xdr Agent | >=7.3<7.3.2 | |
Microsoft Windows |
This issue is fixed in Cortex XDR agent 5.0.12, Cortex XDR agent 6.1.9, Cortex XDR agent 7.2.4, Cortex XDR agent 7.3.2, and all later Cortex XDR agent versions.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2022-0012.
The title of this vulnerability is 'An improper link resolution before file access vulnerability exists in the Palo Alto Networks Cortex XDR agent'.
The severity of CVE-2022-0012 is high with a CVSS score of 7.1.
CVE-2022-0012 enables a local user to delete arbitrary system files and impact the system integrity or cause a denial of service condition.
The Palo Alto Networks Cortex XDR agent versions 5.0 to 5.0.12, 6.1 to 6.1.9, 7.2 to 7.2.4, and 7.3 to 7.3.2 are affected by CVE-2022-0012.
To fix this vulnerability, update the Palo Alto Networks Cortex XDR agent to a version that is not vulnerable.
More information about CVE-2022-0012 can be found at the following link: https://security.paloaltonetworks.com/CVE-2022-0012