Lucene search

K
nvd[email protected]NVD:CVE-2024-5909
HistoryJun 12, 2024 - 5:15 p.m.

CVE-2024-5909

2024-06-1217:15:53
CWE-269
web.nvd.nist.gov
9
palo alto networks
cortex xdr
windows
vulnerability
malware

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS

0

Percentile

9.0%

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.

Affected configurations

Nvd
Node
paloaltonetworkscortex_xdr_agentRange7.97.9.102critical_environmentwindows
OR
paloaltonetworkscortex_xdr_agentRange8.18.1.2windows
OR
paloaltonetworkscortex_xdr_agentRange8.28.2.1windows
VendorProductVersionCPE
paloaltonetworkscortex_xdr_agent*cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:*:*:*:*:critical_environment:windows:*:*
paloaltonetworkscortex_xdr_agent*cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:*:*:*:*:*:windows:*:*

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS

0

Percentile

9.0%

Related for NVD:CVE-2024-5909