Palo Alto Networks Cortex XDR是马来西亚Palo Alto Networks公司的一个用于基于远程端点检测的安全运营平台。 Palo Alto Networks Cortex XDR 代理中存在代码问题漏洞,该漏洞允许在 Windows 根目录(例如 C:)中具有文件创建权限的本地攻击者能够存储一个程序,然后该程序可能会在以下情况下被另一个本地用户无意执行该用户使用实时终端会话。此问题影响: Cortex XDR 代理 5.0 版本早于 Cortex XDR 代理 5.0.12
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Palo Alto Networks | Cortex XDR Agent | 7.4.* | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-0015 | 7.8 HIGH | Cortex XDR Agent: An Uncontrolled Search Path Element Leads to Local Privilege Escalation |
| CVE-2022-0012 | 6.1 MEDIUM | Cortex XDR Agent: Local Arbitrary File Deletion Vulnerability |
| CVE-2022-0013 | 5.0 MEDIUM | Cortex XDR Agent: File Information Exposure Vulnerability When Generating Support File |
No comments yet