A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to disable the agent. This vulnerability can also be leveraged by malware to disable the Cortex XDR agent and then perform malicious activity.
History

Thu, 20 Feb 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Feb 2025 00:00:00 +0000

Type Values Removed Values Added
Description A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to disable the agent. This vulnerability can also be leveraged by malware to disable the Cortex XDR agent and then perform malicious activity.
Title Cortex XDR Agent: Local Windows User Can Disable the Agent
First Time appeared Paloaltonetworks
Paloaltonetworks cortex Xdr Agent
Weaknesses CWE-754
CPEs cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:8.3:CE:*:*:*:*:*:*
cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:8.4.*:*:*:*:*:*:*:*
cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:8.5.0:*:*:*:*:*:*:*
Vendors & Products Paloaltonetworks
Paloaltonetworks cortex Xdr Agent
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/AU:Y/R:U/V:D/U:Amber'}


cve-icon MITRE

Status: PUBLISHED

Assigner: palo_alto

Published:

Updated: 2025-02-20T17:23:01.176Z

Reserved: 2024-12-20T23:23:14.201Z

Link: CVE-2025-0112

cve-icon Vulnrichment

Updated: 2025-02-20T17:22:58.057Z

cve-icon NVD

Status : Received

Published: 2025-02-20T00:15:20.640

Modified: 2025-02-20T00:15:20.640

Link: CVE-2025-0112

cve-icon Redhat

No data.