CVE-2025-0112: Cortex XDR Agent: Local Windows User Can Disable the Agent (Severity: MEDIUM)
A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to disable the agent. This vulnerability can also be leveraged by malware to disable the Cortex XDR agent and then perform malicious activity.
Affected Software
Remediation
Mitigation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0112?
CVE-2025-0112 has a moderate severity level due to the potential for exploitation by malware to disable security features.
How do I fix CVE-2025-0112?
To fix CVE-2025-0112, update the Palo Alto Networks Cortex XDR agent to version 8.5.1 or higher.
Who is impacted by CVE-2025-0112?
CVE-2025-0112 impacts users of the Palo Alto Networks Cortex XDR Agent on Windows devices.
Can non-administrative Windows users exploit CVE-2025-0112?
Yes, non-administrative Windows users can exploit CVE-2025-0112 to disable the Cortex XDR agent.
What types of devices are affected by CVE-2025-0112?
CVE-2025-0112 affects Windows devices running the vulnerable versions of Palo Alto Networks Cortex XDR Agent.