CVE-2022-0025: Cortex XDR Agent: An Uncontrolled Search Path Element Leads to Local Privilege Escalation (PE) Vulnerability
A local privilege escalation (PE) vulnerability exists in Palo Alto Networks Cortex XDR agent software on Windows that enables an authenticated local user with file creation privilege in the Windows root directory (such as C:\) to execute a program with elevated privileges. This issue impacts: All versions of the Cortex XDR agent when upgrading to Cortex XDR agent 7.7.0 on Windows; Cortex XDR agent 7.7.0 without content update 500 or a later version on Windows. This issue does not impact other platforms or other versions of the Cortex XDR agent.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-0025?
CVE-2022-0025 is a local privilege escalation vulnerability in Palo Alto Networks Cortex XDR agent software on Windows.
Who is affected by CVE-2022-0025?
Users of Palo Alto Networks Cortex XDR agent software on Windows versions 7.7.0 to 7.7.1.62043 are affected by CVE-2022-0025.
What is the severity of CVE-2022-0025?
CVE-2022-0025 has a severity rating of 6.7 (high).
How does CVE-2022-0025 work?
CVE-2022-0025 allows an authenticated local user with file creation privilege in the Windows root directory to execute a program with elevated privileges.
How can I fix CVE-2022-0025?
To fix CVE-2022-0025, users should update Palo Alto Networks Cortex XDR agent software to a version higher than 7.7.1.62043.