CVE-2020-2049
Published: Dec 9, 2020
Modified: Sep 17, 2024
CVSS v3.1
7.8
Description
A local privilege escalation vulnerability exists in Palo Alto Networks Cortex XDR Agent on the Windows platform that allows an authenticated local Windows user to execute programs with SYSTEM privileges. This requires the user to have the privilege to create files in the Windows root directory. This issue impacts: All versions of Cortex XDR Agent 7.1 with content update 149 and earlier versions; All versions of Cortex XDR Agent 7.2 with content update 149 and earlier versions.
| Vendor | Product | Versions |
|---|---|---|
Palo Alto Networks | Cortex XDR Agent | unaffected 7.1.* with content update 150affected 7.1.* without content update 150unaffected 7.2.* with content update 150affected 7.2.* without content update 150 |
Palo Alto Networks | Cortex XDR Agent | unaffected 6.1.* with latest contentunaffected 7.0.* with latest content |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now