CVE-2022-0029Medium
CVE-2022-0029 Cortex XDR Agent: Improper Link Resolution Vulnerability When Generating a Tech Support File
Published
September 14, 2022
Last Modified
September 14, 2022
🔗 CVE IDs covered (1)
📋 Description
An improper link resolution vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local attacker to read files on the system with elevated privileges when generating a tech support file.
🎯 Affected products1
- Cortex XDR Agent
✅ Remediation
This issue is fixed in Cortex XDR agent 5.0.12-hotfix update, Cortex XDR agent 7.5.101-CE, Cortex XDR agent 7.7.3, and all later versions of the Cortex XDR agent.