CVE-2022-0014: Cortex XDR Agent: Unintended Program Execution When Using Live Terminal Session
An untrusted search path vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables a local attacker with file creation privilege in the Windows root directory (such as C:\) to store a program that can then be unintentionally executed by another local user when that user utilizes a Live Terminal session. This issue impacts: Cortex XDR agent 5.0 versions earlier than Cortex XDR agent 5.0.12; Cortex XDR agent 6.1 versions earlier than Cortex XDR agent 6.1.9; Cortex XDR agent 7.2 versions earlier than Cortex XDR agent 7.2.4; Cortex XDR agent 7.3 versions earlier than Cortex XDR agent 7.3.2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-0014?
CVE-2022-0014 is an untrusted search path vulnerability in the Palo Alto Networks Cortex XDR agent, allowing a local attacker to store and execute a program unintentionally by another local user.
How does CVE-2022-0014 impact Palo Alto Networks Cortex XDR agent?
CVE-2022-0014 allows a local attacker with file creation privilege in the Windows root directory to execute a program unintentionally by another local user.
Which versions of Palo Alto Networks Cortex XDR agent are affected by CVE-2022-0014?
Versions 5.0 to 5.0.12, 6.1 to 6.1.9, 7.2 to 7.2.4, and 7.3 to 7.3.2 of Palo Alto Networks Cortex XDR agent are affected by CVE-2022-0014.
What is the severity level of CVE-2022-0014?
CVE-2022-0014 has a severity level of 7.3 (high).
Where can I find more information about CVE-2022-0014?
More information about CVE-2022-0014 can be found at the following link: [https://security.paloaltonetworks.com/CVE-2022-0014](https://security.paloaltonetworks.com/CVE-2022-0014)