CVE-2024-5909

EUVD-2024-47041
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 74%
Affected Products (NVD)
VendorProductVersion
paloaltonetworkscortex_xdr_agent
7.9 ≤
𝑥
< 7.9.102
paloaltonetworkscortex_xdr_agent
8.1 ≤
𝑥
< 8.1.2
paloaltonetworkscortex_xdr_agent
8.2 ≤
𝑥
< 8.2.1
𝑥
= Vulnerable software versions