CVE-2025-0112

MEDIUM

Palo Alto Networks Cortex XDR - Privilege Escalation

Title source: llm
STIX 2.1

Description

A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to disable the agent. This vulnerability can also be leveraged by malware to disable the Cortex XDR agent and then perform malicious activity.

Scores

CVSS v4 6.8
EPSS 0.0011
EPSS Percentile 28.9%
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/AU:Y/R:U/V:D/U:Amber

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-754
Status published
Products (4)
Palo Alto Networks/Cortex XDR Agent 8.3-CE - 8.3.101-CE
Palo Alto Networks/Cortex XDR Agent 8.4.0
Palo Alto Networks/Cortex XDR Agent 8.5.0 - 8.5.1
Palo Alto Networks/Cortex XDR Agent 8.6.0
Published Feb 20, 2025
Tracked Since Feb 18, 2026