CVE-2023-0002 is a high-severity vulnerability affecting Palo Alto Networks Cortex XDR agents on Windows devices. A local attacker can exploit a flaw in the agent's protection mechanism to execute privileged cytool commands, enabling them to disable or uninstall the agent. This local privilege escalation (CVSS 7.8) allows for complete compromise of the agent's functionality, leading to high impact on confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.0, < 5.0.12.22203CPE matchmatch criteria | cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:*:*:*:*:*:*:*:* | ||
>= 7.5, <= 7.5.101CPE matchmatch criteria | cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:*:*:*:*:critical_environment:*:*:* | ||
>= 7.5, < 7.5.101-CECPE match | cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.