Vulnerability Description
A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables an authenticated local user to execute programs with elevated privileges. This issue impacts: Cortex XDR agent 5.0 versions earlier than Cortex XDR agent 5.0.12; Cortex XDR agent 6.1 versions earlier than Cortex XDR agent 6.1.9.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Paloaltonetworks | Cortex Xdr Agent | >= 5.0, < 5.0.12 |
Related Weaknesses (CWE)
References
- https://security.paloaltonetworks.com/CVE-2022-0015Vendor Advisory
- https://security.paloaltonetworks.com/CVE-2022-0015Vendor Advisory
FAQ
What is CVE-2022-0015?
CVE-2022-0015 is a vulnerability with a CVSS score of 7.8 (HIGH). A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables an authenticated local user to execute programs with elevated privileges. This issue impa...
How severe is CVE-2022-0015?
CVE-2022-0015 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-0015?
Check the references section above for vendor advisories and patch information. Affected products include: Paloaltonetworks Cortex Xdr Agent.