CVE-2024-5909
MEDIUMPaloaltonetworks Cortex Xdr Agent - Improper Privilege Management
Title source: ruleDescription
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.
Exploits (1)
Scores
CVSS v3
5.5
EPSS
0.0086
EPSS Percentile
75.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-269
Status
published
Products (2)
paloaltonetworks/cortex_xdr_agent
7.9 - 7.9.102
paloaltonetworks/cortex_xdr_agent
8.1 - 8.1.2
Published
Jun 12, 2024
Tracked Since
Feb 18, 2026