CVE-2023-0002: Cortex XDR Agent: Product Disruption by Local Windows User
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user to execute privileged cytool commands that disable or uninstall the agent.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0002?
The severity of CVE-2023-0002 is high, with a CVSS score of 7.8.
What is the affected software for CVE-2023-0002?
The affected software for CVE-2023-0002 is Palo Alto Networks Cortex XDR agent on Windows devices.
How can a local user exploit CVE-2023-0002?
A local user can exploit CVE-2023-0002 by executing privileged cytool commands that disable or uninstall the Palo Alto Networks Cortex XDR agent.
How can I fix CVE-2023-0002?
To fix CVE-2023-0002, update the Palo Alto Networks Cortex XDR agent to version 5.0.12.22203 or later.
Where can I find more information about CVE-2023-0002?
For more information about CVE-2023-0002, you can refer to the Palo Alto Networks security advisory at https://security.paloaltonetworks.com/CVE-2023-0002.