CVE-2022-0029

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
14/09/2022
Last modified:
17/09/2022

Description

An improper link resolution vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local attacker to read files on the system with elevated privileges when generating a tech support file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:*:*:*:*:*:*:*:* 5.0 (including) 5.0.12 (excluding)
cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:*:*:*:*:critical_environment:*:*:* 7.5 (including) 7.5.101 (excluding)
cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:*:*:*:*:*:*:*:* 7.7 (including) 7.7.3 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools