First published: Wed Oct 09 2024(Updated: )
A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.
Credit: psirt@paloaltonetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Any of | ||
Paloaltonetworks Cortex Xdr Agent | >=7.9<7.9.102 | |
Paloaltonetworks Cortex Xdr Agent | =8.3.0 | |
Paloaltonetworks Cortex Xdr Agent | =8.4.0 | |
Microsoft Windows | ||
All of | ||
Palo Alto Networks Cortex XDR agent | <7.9.102-CE=7.9-CE | 7.9.102-CE |
Microsoft Windows | * | |
Palo Alto Networks Cortex XDR agent |
This issue is fixed in Cortex XDR Agent 7.9.102-CE, Cortex XDR Agent 8.3.1, Cortex XDR Agent 8.4.1, and all later Cortex XDR Agent versions.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-9469 has been classified as a significant vulnerability due to its potential to allow malware to disable important security features.
To mitigate CVE-2024-9469, ensure that the Cortex XDR Agent is updated to a version higher than 8.4.0 or 7.9.102.
CVE-2024-9469 affects users of the Palo Alto Networks Cortex XDR Agent on Windows devices with specific versions.
The implications of CVE-2024-9469 include an increased risk of malware disabling security agents, leading to potential data breaches.
If you are running Cortex XDR Agent versions 7.9 through 7.9.102 or 8.3.0, then your system is at risk from CVE-2024-9469.