Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Cortex XDR Agent: Unintended Program Execution When Using Live Terminal Session
Vulnerability Description
An untrusted search path vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables a local attacker with file creation privilege in the Windows root directory (such as C:\) to store a program that can then be unintentionally executed by another local user when that user utilizes a Live Terminal session. This issue impacts: Cortex XDR agent 5.0 versions earlier than Cortex XDR agent 5.0.12; Cortex XDR agent 6.1 versions earlier than Cortex XDR agent 6.1.9; Cortex XDR agent 7.2 versions earlier than Cortex XDR agent 7.2.4; Cortex XDR agent 7.3 versions earlier than Cortex XDR agent 7.3.2.
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
不可信的搜索路径
Vulnerability Title
Palo Alto Networks Cortex XDR 代码问题漏洞
Vulnerability Description
Palo Alto Networks Cortex XDR是马来西亚Palo Alto Networks公司的一个用于基于远程端点检测的安全运营平台。 Palo Alto Networks Cortex XDR 代理中存在代码问题漏洞,该漏洞允许在 Windows 根目录(例如 C:)中具有文件创建权限的本地攻击者能够存储一个程序,然后该程序可能会在以下情况下被另一个本地用户无意执行该用户使用实时终端会话。此问题影响: Cortex XDR 代理 5.0 版本早于 Cortex XDR 代理 5.0.12
CVSS Information
N/A
Vulnerability Type
N/A