First published: Wed Jun 12 2024(Updated: )
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local low privileged Windows user to disrupt some functionality of the agent. However, they are not able to disrupt Cortex XDR agent protection mechanisms using this vulnerability.
Credit: psirt@paloaltonetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Palo Alto Networks Cortex XDR Agent | >=7.9.0<7.9.102 | |
Palo Alto Networks Cortex XDR Agent | >=8.1<8.1.2 | |
Palo Alto Networks Cortex XDR Agent | >=8.2<8.2.1 |
This issue is fixed in Cortex XDR agent 7.9.102-CE, Cortex XDR agent 8.1.2, Cortex XDR agent 8.2.1, and all later Cortex XDR agent versions.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-5905 has a medium severity level due to the potential disruption of Cortex XDR agent functionality.
To mitigate CVE-2024-5905, update the Cortex XDR agent to a version above 7.9.102, 8.1.2, or 8.2.1.
CVE-2024-5905 affects versions 7.9.0 to 7.9.102, 8.1.0 to 8.1.2, and 8.2.0 to 8.2.1 of the Cortex XDR agent.
Yes, a local low privileged Windows user can disrupt some functionalities of the Cortex XDR agent through CVE-2024-5905.
No, while CVE-2024-5905 allows disruption of certain functionalities, it does not affect the core protection mechanisms of the Cortex XDR agent.