Palo Alto 安全中心 2024年07月04日
CVE-2024-5905 Cortex XDR Agent: Local Windows User Can Disrupt Functionality of the Agent (Severity: LOW)
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

Palo Alto Networks Cortex XDR Agent在Windows设备上存在一个保护机制问题,允许本地低权限Windows用户破坏代理的部分功能。但是,他们无法使用此漏洞破坏Cortex XDR代理的保护机制。

😈 **漏洞描述:** Palo Alto Networks Cortex XDR Agent在Windows设备上存在一个保护机制问题,允许本地低权限Windows用户破坏代理的部分功能。但攻击者无法使用此漏洞破坏Cortex XDR代理的保护机制。

😎 **受影响版本:** Cortex XDR Agent 8.2版本低于8.2.1的Windows版本,Cortex XDR Agent 8.1版本低于8.1.2的Windows版本,以及Cortex XDR Agent 7.9-CE版本低于7.9.102-CE的Windows版本受到影响。

🤩 **解决方案:** 此问题已在Cortex XDR Agent 7.9.102-CE、Cortex XDR Agent 8.1.2、Cortex XDR Agent 8.2.1以及所有更高版本的Cortex XDR Agent中修复。

😔 **影响:** 攻击者可以利用此漏洞破坏代理的部分功能,但无法破坏Cortex XDR代理的保护机制。

🙏 **致谢:** Palo Alto Networks感谢VUREX(InfoGuard AG)的Manuel Feifel发现并报告了此问题。

Palo Alto Networks Security Advisories /CVE-2024-5905CVE-2024-5905 Cortex XDR Agent: Local Windows User Can Disrupt Functionality of the AgentUrgencyMODERATEResponse EffortMODERATERecoveryUSERValue DensityDIFFUSEAttack VectorLOCALAttack ComplexityHIGHAttack RequirementsNONEAutomatableYESUser InteractionNONEProduct ConfidentialityNONEProduct IntegrityLOWProduct AvailabilityLOWPrivileges RequiredLOWSubsequent ConfidentialityNONESubsequent IntegrityNONESubsequent AvailabilityNONENVDJSON Published2024-06-12 Updated2024-06-12ReferenceCPATR-21727DiscoveredexternallyDescriptionA problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local low privileged Windows user to disrupt some functionality of the agent. However, they are not able to disrupt Cortex XDR agent protection mechanisms using this vulnerability.Product StatusVersionsAffectedUnaffectedCortex XDR Agent 8.4NoneAllCortex XDR Agent 8.3NoneAllCortex XDR Agent 8.2< 8.2.1 on Windows>= 8.2.1 on WindowsCortex XDR Agent 8.1< 8.1.2 on Windows>= 8.1.2 on WindowsCortex XDR Agent 7.9-CE< 7.9.102-CE on Windows>= 7.9.102-CE on WindowsSeverity:LOWCVSSv4.0Base Score:2 (CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/AU:Y/R:U/V:D/RE:M/U:Amber)Exploitation StatusPalo Alto Networks is not aware of any malicious exploitation of this issue.Weakness TypeCWE-346 Origin Validation ErrorSolutionThis issue is fixed in Cortex XDR agent 7.9.102-CE, Cortex XDR agent 8.1.2, Cortex XDR agent 8.2.1, and all later Cortex XDR agent versions.AcknowledgmentsPalo Alto Networks thanks Manuel Feifel of VUREX (InfoGuard AG) for discovering and reporting this issue.Timeline2024-06-12Initial publication

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

Cortex XDR Agent 漏洞 CVE-2024-5905 Windows 安全
相关文章