CVE-2025-0121

A null pointer dereference vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low-privileged local Windows user to crash the agent. Additionally, malware can use this vulnerability to perform malicious activity without Cortex XDR being able to detect it.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
UNKNOWN
---
palo_altoCNA
---
---
CISA-ADPADP
---
---