Palo Alto 安全中心 2024年07月11日
CVE-2024-5912 Cortex XDR Agent: Improper File Signature Verification Checks (Severity: MEDIUM)
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

Palo Alto Networks Cortex XDR Agent存在一个文件签名验证错误,攻击者可以利用此漏洞绕过Cortex XDR Agent的可执行文件阻止功能,并在设备上运行不受信任的可执行文件。攻击者可以利用此漏洞执行不受信任的软件,而不会被检测或阻止。

🤔 **文件签名验证错误:** Cortex XDR Agent的代码中存在一个文件签名验证错误,攻击者可以通过伪造文件签名来绕过安全检查。

🛡️ **绕过阻止功能:** 攻击者可以利用此漏洞绕过Cortex XDR Agent的可执行文件阻止功能,在设备上运行不受信任的可执行文件。

⚠️ **潜在风险:** 攻击者可以使用此漏洞来执行恶意软件,窃取敏感数据,或破坏系统。

🛠️ **修复建议:** Palo Alto Networks已经发布了修复此漏洞的补丁,建议用户尽快更新到最新版本的Cortex XDR Agent。

🤝 **感谢:** Palo Alto Networks感谢BITMARCK的Cyber Defence Center,特别是Maximilan Pappert发现了并报告了此问题。

Palo Alto Networks Security Advisories /CVE-2024-5912CVE-2024-5912 Cortex XDR Agent: Improper File Signature Verification ChecksUrgencyMODERATEResponse EffortMODERATERecoveryUSERValue DensityCONCENTRATEDAttack VectorLOCALAttack ComplexityLOWAttack RequirementsNONEAutomatableNOUser InteractionNONEProduct ConfidentialityNONEProduct IntegrityHIGHProduct AvailabilityNONEPrivileges RequiredLOWSubsequent ConfidentialityNONESubsequent IntegrityNONESubsequent AvailabilityNONENVDJSON Published2024-07-10 Updated2024-07-10ReferenceCPATR-22565DiscoveredexternallyDescriptionAn improper file signature check in Palo Alto Networks Cortex XDR agent may allow an attacker to bypass the Cortex XDR agent's executable blocking capabilities and run untrusted executables on the device. This issue can be leveraged to execute untrusted software without being detected or blocked.Product StatusVersionsAffectedUnaffectedCortex XDR Agent 8.4NoneAllCortex XDR Agent 8.3-CENoneAllCortex XDR Agent 8.3NoneAllCortex XDR Agent 8.2< 8.2.2>= 8.2.2Cortex XDR Agent 7.9< 7.9.102-CE>= 7.9.102-CESeverity:MEDIUMCVSSv4.0Base Score:6.8 (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/AU:N/R:U/V:C/RE:M/U:Amber)Exploitation StatusPalo Alto Networks is not aware of any malicious exploitation of this issue.Weakness TypeCWE-347 Improper Verification of Cryptographic SignatureSolutionThis issue is fixed in Cortex XDR agent 7.9.102-CE, Cortex XDR agent 8.1.3, Cortex XDR agent 8.2.2, and all later Cortex XDR agent versions.AcknowledgmentsPalo Alto Networks thanks the Cyber Defence Center of BITMARCK, and especially Maximilan Pappert for discovering and reporting this issue.Timeline2024-07-10Initial publication

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

Cortex XDR Agent 漏洞 CVE-2024-5912 安全 文件签名验证
相关文章