CVE-2024-8690: Cortex XDR Agent: Local Windows Administrator Can Disable the Agent (Severity: MEDIUM)
A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows administrator privileges to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8690?
CVE-2024-8690 is considered a critical vulnerability affecting the Palo Alto Networks Cortex XDR agent.
How do I fix CVE-2024-8690?
To remediate CVE-2024-8690, ensure that the Cortex XDR agent is updated to the latest version that addresses this vulnerability.
Who is affected by CVE-2024-8690?
CVE-2024-8690 affects users with Windows administrator privileges who have the Palo Alto Networks Cortex XDR agent installed.
What can someone do to mitigate the risk of CVE-2024-8690?
To mitigate the risk of CVE-2024-8690, restrict administrative access and monitor for unauthorized attempts to disable the Cortex XDR agent.
Is there a known exploit for CVE-2024-8690?
While specific exploits for CVE-2024-8690 have not been publicly disclosed, the vulnerability could be leveraged by malware to disable the security agent.