imPC@ndo IT

Tracker / CVE-2024-5907

CVE-2024-5907

High 7.0

A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices enables a local user to execute programs with elevated privileges. However, execution does require the local user to successfully exploit a race condition, which makes this vulnerability difficult to exploit.

Affected products and versions

paloaltonetworks cortex_xdr_agent · 7.9 → 7.9.102
paloaltonetworks cortex_xdr_agent · 8.1 → 8.2.3
paloaltonetworks cortex_xdr_agent · 8.3 → 8.3.1

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References