CVE-2022-0029

An improper link resolution vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local attacker to read files on the system with elevated privileges when generating a tech support file.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
palo_altoCNA
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 14%
VendorProductVersion
paloaltonetworkscortex_xdr_agent
5.0 ≤
𝑥
< 5.0.12
paloaltonetworkscortex_xdr_agent
7.5 ≤
𝑥
< 7.5.101
paloaltonetworkscortex_xdr_agent
7.7 ≤
𝑥
< 7.7.3
𝑥
= Vulnerable software versions