CVE-2022-0029Medium

CVE-2022-0029 Cortex XDR Agent: Improper Link Resolution Vulnerability When Generating a Tech Support File

Published
September 14, 2022
Last Modified
September 14, 2022

🔗 CVE IDs covered (1)

📋 Description

An improper link resolution vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local attacker to read files on the system with elevated privileges when generating a tech support file.

🎯 Affected products1

  • Cortex XDR Agent

✅ Remediation

This issue is fixed in Cortex XDR agent 5.0.12-hotfix update, Cortex XDR agent 7.5.101-CE, Cortex XDR agent 7.7.3, and all later versions of the Cortex XDR agent.

🔗 References (1)