First published: Wed May 11 2022(Updated: )
A local privilege escalation (PE) vulnerability exists in Palo Alto Networks Cortex XDR agent software on Windows that enables an authenticated local user with file creation privilege in the Windows root directory (such as C:\) to execute a program with elevated privileges. This issue impacts all versions of Cortex XDR agent without content update 330 or a later content update version.
Credit: psirt@paloaltonetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Paloaltonetworks Cortex Xdr Agent | =6.1 | |
Paloaltonetworks Cortex Xdr Agent | =6.1-content_update330 | |
Paloaltonetworks Cortex Xdr Agent | =6.1.4-content_update330 | |
Paloaltonetworks Cortex Xdr Agent | =6.1.4-hotfix | |
Paloaltonetworks Cortex Xdr Agent | =6.1.5 | |
Paloaltonetworks Cortex Xdr Agent | =6.1.5-content_update330 | |
Paloaltonetworks Cortex Xdr Agent | =6.1.5-hotfix | |
Paloaltonetworks Cortex Xdr Agent | =6.1.6 | |
Paloaltonetworks Cortex Xdr Agent | =6.1.6-content_update330 | |
Paloaltonetworks Cortex Xdr Agent | =6.1.7 | |
Paloaltonetworks Cortex Xdr Agent | =6.1.7-content_update330 | |
Paloaltonetworks Cortex Xdr Agent | =6.1.8 | |
Paloaltonetworks Cortex Xdr Agent | =6.1.8-content_update330 | |
Paloaltonetworks Cortex Xdr Agent | =6.1.9 | |
Paloaltonetworks Cortex Xdr Agent | =6.1.9-content_update330 | |
Paloaltonetworks Cortex Xdr Agent | =7.4.1 | |
Paloaltonetworks Cortex Xdr Agent | =7.4.1-content_update330 | |
Paloaltonetworks Cortex Xdr Agent | =7.4.2 | |
Paloaltonetworks Cortex Xdr Agent | =7.4.2-content_update330 | |
Paloaltonetworks Cortex Xdr Agent | =7.4.3 | |
Paloaltonetworks Cortex Xdr Agent | =7.4.3-content_update330 | |
Paloaltonetworks Cortex Xdr Agent | =7.4.4 | |
Paloaltonetworks Cortex Xdr Agent | =7.4.4-content_update330 | |
Paloaltonetworks Cortex Xdr Agent | =7.5 | |
Paloaltonetworks Cortex Xdr Agent | =7.5.1 | |
Paloaltonetworks Cortex Xdr Agent | =7.5.1-content_update330 | |
Paloaltonetworks Cortex Xdr Agent | =7.5.2 | |
Paloaltonetworks Cortex Xdr Agent | =7.5.2-content_update330 | |
Paloaltonetworks Cortex Xdr Agent | =7.5.3 | |
Paloaltonetworks Cortex Xdr Agent | =7.5.3-content_update330 | |
Paloaltonetworks Cortex Xdr Agent | =7.6.1 | |
Paloaltonetworks Cortex Xdr Agent | =7.6.1-content_update330 | |
Paloaltonetworks Cortex Xdr Agent | =7.6.2 | |
Paloaltonetworks Cortex Xdr Agent | =7.6.2-content_update330 | |
Paloaltonetworks Cortex Xdr Agent | =7.7 | |
Paloaltonetworks Cortex Xdr Agent | =7.7-content_update330 | |
Paloaltonetworks Cortex Xdr Agent | =7.7.1 | |
Paloaltonetworks Cortex Xdr Agent | =7.7.1-content_update330 | |
Microsoft Windows |
This issue is fixed in all Cortex XDR agent versions with content update 330 and later content update versions.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0026 is a local privilege escalation vulnerability in Palo Alto Networks Cortex XDR agent software on Windows.
CVE-2022-0026 allows an authenticated local user with file creation privilege in the Windows root directory to execute a program with elevated privileges.
CVE-2022-0026 impacts Palo Alto Networks Cortex XDR agent software version 6.1.
CVE-2022-0026 has a severity rating of 6.7 (high).
For more information about CVE-2022-0026, you can visit the following link: https://security.paloaltonetworks.com/CVE-2022-0026