CVE-2024-5907: Cortex XDR Agent: Local Privilege Escalation (PE) Vulnerability
A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices enables a local user to execute programs with elevated privileges. However, execution does require the local user to successfully exploit a race condition, which makes this vulnerability difficult to exploit.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Palo Alto Networks Cortex XDR agent (Windows)to a version that resolves this vulnerability.Fixed in 7.9.102-CE - Upgrade
Upgrade
Palo Alto Networks Cortex XDR agent (Windows)to a version that resolves this vulnerability.Fixed in 8.2.3 - Upgrade
Upgrade
Palo Alto Networks Cortex XDR agent (Windows)to a version that resolves this vulnerability.Fixed in 8.3.1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5907?
CVE-2024-5907 is categorized as a privilege escalation vulnerability.
How do I fix CVE-2024-5907?
To mitigate CVE-2024-5907, update the Palo Alto Networks Cortex XDR agent to a version that addresses this vulnerability.
What systems are affected by CVE-2024-5907?
CVE-2024-5907 affects the Palo Alto Networks Cortex XDR agent on Windows devices.
Can CVE-2024-5907 be exploited remotely?
No, CVE-2024-5907 requires local access to exploit the race condition.
What types of privileges can be escalated via CVE-2024-5907?
CVE-2024-5907 allows local users to execute programs with elevated privileges.