// For flags

CVE-2022-0026

Cortex XDR Agent: Unintended Program Execution Leads to Local Privilege Escalation (PE) Vulnerability

Severity Score

6.7
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A local privilege escalation (PE) vulnerability exists in Palo Alto Networks Cortex XDR agent software on Windows that enables an authenticated local user with file creation privilege in the Windows root directory (such as C:\) to execute a program with elevated privileges. This issue impacts all versions of Cortex XDR agent without content update 330 or a later content update version.

Se presenta una vulnerabilidad de escalada de privilegios (PE) local en el software Cortex XDR agent de Palo Alto Networks en Windows que permite a un usuario local autenticado con privilegios de creación de archivos en el directorio root de Windows (como C:\) ejecutar un programa con altos privilegios. Este problema afecta a todas las versiones de Cortex XDR agent sin la actualización de contenido 330 o una versión posterior de actualización de contenido

*Credits: Palo Alto Networks thanks Xavier DANEST of Decathlon and Yasser Alhazmi for discovering and reporting this issue.
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-12-28 CVE Reserved
  • 2022-05-11 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-09-17 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-282: Improper Ownership Management
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
6.1
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "6.1"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
6.1
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "6.1"
content_update330
Safe
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
6.1.4
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "6.1.4"
content_update330
Safe
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
6.1.4
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "6.1.4"
hotfix
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
6.1.5
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "6.1.5"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
6.1.5
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "6.1.5"
content_update330
Safe
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
6.1.5
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "6.1.5"
hotfix
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
6.1.6
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "6.1.6"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
6.1.6
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "6.1.6"
content_update330
Safe
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
6.1.7
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "6.1.7"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
6.1.7
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "6.1.7"
content_update330
Safe
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
6.1.8
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "6.1.8"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
6.1.8
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "6.1.8"
content_update330
Safe
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
6.1.9
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "6.1.9"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
6.1.9
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "6.1.9"
content_update330
Safe
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
7.4.1
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "7.4.1"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
7.4.1
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "7.4.1"
content_update330
Safe
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
7.4.2
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "7.4.2"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
7.4.2
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "7.4.2"
content_update330
Safe
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
7.4.3
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "7.4.3"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
7.4.3
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "7.4.3"
content_update330
Safe
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
7.4.4
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "7.4.4"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
7.4.4
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "7.4.4"
content_update330
Safe
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
7.5
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "7.5"
content_engine
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
7.5.1
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "7.5.1"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
7.5.1
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "7.5.1"
content_update330
Safe
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
7.5.2
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "7.5.2"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
7.5.2
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "7.5.2"
content_update330
Safe
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
7.5.3
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "7.5.3"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
7.5.3
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "7.5.3"
content_update330
Safe
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
7.6.1
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "7.6.1"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
7.6.1
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "7.6.1"
content_update330
Safe
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
7.6.2
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "7.6.2"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
7.6.2
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "7.6.2"
content_update330
Safe
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
7.7
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "7.7"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
7.7
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "7.7"
content_update330
Safe
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
7.7.1
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "7.7.1"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Paloaltonetworks
Search vendor "Paloaltonetworks"
Cortex Xdr Agent
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent"
7.7.1
Search vendor "Paloaltonetworks" for product "Cortex Xdr Agent" and version "7.7.1"
content_update330
Safe
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe