CVE-2022-0026: Cortex XDR Agent: Unintended Program Execution Leads to Local Privilege Escalation (PE) Vulnerability
A local privilege escalation (PE) vulnerability exists in Palo Alto Networks Cortex XDR agent software on Windows that enables an authenticated local user with file creation privilege in the Windows root directory (such as C:\) to execute a program with elevated privileges. This issue impacts all versions of Cortex XDR agent without content update 330 or a later content update version.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-0026?
CVE-2022-0026 is a local privilege escalation vulnerability in Palo Alto Networks Cortex XDR agent software on Windows.
How does CVE-2022-0026 impact Palo Alto Networks Cortex XDR agent software?
CVE-2022-0026 allows an authenticated local user with file creation privilege in the Windows root directory to execute a program with elevated privileges.
Which version of Palo Alto Networks Cortex XDR agent software is affected by CVE-2022-0026?
CVE-2022-0026 impacts Palo Alto Networks Cortex XDR agent software version 6.1.
What is the severity of CVE-2022-0026?
CVE-2022-0026 has a severity rating of 6.7 (high).
Where can I find more information about CVE-2022-0026?
For more information about CVE-2022-0026, you can visit the following link: https://security.paloaltonetworks.com/CVE-2022-0026