First published: Wed Jan 12 2022(Updated: )
An untrusted search path vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables a local attacker with file creation privilege in the Windows root directory (such as C:\) to store a program that can then be unintentionally executed by another local user when that user utilizes a Live Terminal session. This issue impacts: Cortex XDR agent 5.0 versions earlier than Cortex XDR agent 5.0.12; Cortex XDR agent 6.1 versions earlier than Cortex XDR agent 6.1.9; Cortex XDR agent 7.2 versions earlier than Cortex XDR agent 7.2.4; Cortex XDR agent 7.3 versions earlier than Cortex XDR agent 7.3.2.
Credit: psirt@paloaltonetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Paloaltonetworks Cortex Xdr Agent | >=5.0<5.0.12 | |
Paloaltonetworks Cortex Xdr Agent | >=6.1<6.1.9 | |
Paloaltonetworks Cortex Xdr Agent | >=7.2<7.2.4 | |
Paloaltonetworks Cortex Xdr Agent | >=7.3<7.3.2 | |
Microsoft Windows |
This issue is fixed in Cortex XDR agent 5.0.12, Cortex XDR agent 6.1.9, Cortex XDR agent 7.2.4, Cortex XDR agent 7.3.2, and all later Cortex XDR agent versions.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0014 is an untrusted search path vulnerability in the Palo Alto Networks Cortex XDR agent, allowing a local attacker to store and execute a program unintentionally by another local user.
CVE-2022-0014 allows a local attacker with file creation privilege in the Windows root directory to execute a program unintentionally by another local user.
Versions 5.0 to 5.0.12, 6.1 to 6.1.9, 7.2 to 7.2.4, and 7.3 to 7.3.2 of Palo Alto Networks Cortex XDR agent are affected by CVE-2022-0014.
CVE-2022-0014 has a severity level of 7.3 (high).
More information about CVE-2022-0014 can be found at the following link: [https://security.paloaltonetworks.com/CVE-2022-0014](https://security.paloaltonetworks.com/CVE-2022-0014)