imPC@ndo IT

Tracker / CVE-2022-0029

CVE-2022-0029

Medium 5.5

An improper link resolution vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local attacker to read files on the system with elevated privileges when generating a tech support file.

Affected products and versions

paloaltonetworks cortex_xdr_agent · 5.0 → 5.0.12
paloaltonetworks cortex_xdr_agent · 7.5 → 7.5.101
paloaltonetworks cortex_xdr_agent · 7.7 → 7.7.3

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References