CVE-2022-0029: Cortex XDR Agent: Improper Link Resolution Vulnerability When Generating a Tech Support File
An improper link resolution vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local attacker to read files on the system with elevated privileges when generating a tech support file.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-0029?
CVE-2022-0029 is an improper link resolution vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices.
How does CVE-2022-0029 impact the affected software?
CVE-2022-0029 allows a local attacker to read files on the system with elevated privileges when generating a tech support file.
Which software is affected by CVE-2022-0029?
CVE-2022-0029 affects Palo Alto Networks Cortex XDR agent on Windows devices.
What is the severity of CVE-2022-0029?
The severity of CVE-2022-0029 is medium with a CVSS score of 5.5.
How can I fix CVE-2022-0029?
To fix CVE-2022-0029, update to a version of Palo Alto Networks Cortex XDR agent that is not vulnerable.
Is Microsoft Windows affected by CVE-2022-0029?
No, Microsoft Windows is not affected by CVE-2022-0029.
Where can I find more information about CVE-2022-0029?
You can find more information about CVE-2022-0029 on the Palo Alto Networks security website: https://security.paloaltonetworks.com/CVE-2022-0029