First published: Wed Jan 12 2022(Updated: )
A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables an authenticated local user to execute programs with elevated privileges. This issue impacts: Cortex XDR agent 5.0 versions earlier than Cortex XDR agent 5.0.12; Cortex XDR agent 6.1 versions earlier than Cortex XDR agent 6.1.9.
Credit: psirt@paloaltonetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Paloaltonetworks Cortex Xdr Agent | >=5.0<5.0.12 | |
Paloaltonetworks Cortex Xdr Agent | >=6.1<6.1.9 |
This issue is fixed in Cortex XDR agent 5.0.12, Cortex XDR agent 6.1.9, and all later Cortex XDR agent versions.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0015 is a local privilege escalation vulnerability in the Palo Alto Networks Cortex XDR agent that allows authenticated local users to execute programs with elevated privileges.
The Cortex XDR agent 5.0 versions earlier than Cortex XDR agent 5.0.12 and Cortex XDR agent 6.1 versions earlier than Cortex XDR agent 6.1.9 are affected by CVE-2022-0015.
CVE-2022-0015 has a severity value of 7.8, indicating a high severity.
An authenticated local user can exploit CVE-2022-0015 to execute programs with elevated privileges.
Yes, a fix is available for CVE-2022-0015. Users should update their Cortex XDR agent to version 5.0.12 or later for Cortex XDR agent 5.0 versions, and version 6.1.9 or later for Cortex XDR agent 6.1 versions.