CVE-2023-0002

MEDIUM

Palo Alto Networks Cortex XDR < - Privilege Escalation

Title source: llm

Description

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user to execute privileged cytool commands that disable or uninstall the agent.

Scores

CVSS v3 5.5
EPSS 0.0012
EPSS Percentile 30.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Classification

CWE
CWE-693
Status published

Affected Products (2)

paloaltonetworks/cortex_xdr_agent < 5.0.12.22203
paloaltonetworks/cortex_xdr_agent < 7.5.101

Timeline

Published Feb 08, 2023
Tracked Since Feb 18, 2026