First published: Wed Feb 08 2023(Updated: )
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user to execute privileged cytool commands that disable or uninstall the agent.
Credit: psirt@paloaltonetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Paloaltonetworks Cortex Xdr Agent | >=5.0<5.0.12.22203 | |
Paloaltonetworks Cortex Xdr Agent | >=7.5<=7.5.101 | |
Microsoft Windows |
This issue is fixed in Cortex XDR agent 5.0.12.22203, Cortex XDR agent 7.5.101-CE, and all later supported Cortex XDR agent versions.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-0002 is high, with a CVSS score of 7.8.
The affected software for CVE-2023-0002 is Palo Alto Networks Cortex XDR agent on Windows devices.
A local user can exploit CVE-2023-0002 by executing privileged cytool commands that disable or uninstall the Palo Alto Networks Cortex XDR agent.
To fix CVE-2023-0002, update the Palo Alto Networks Cortex XDR agent to version 5.0.12.22203 or later.
For more information about CVE-2023-0002, you can refer to the Palo Alto Networks security advisory at https://security.paloaltonetworks.com/CVE-2023-0002.