We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-0112

Cortex XDR Agent: Local Windows User Can Disable the Agent



Description

A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to disable the agent. This vulnerability can also be leveraged by malware to disable the Cortex XDR agent and then perform malicious activity.

Reserved 2024-12-20 | Published 2025-02-19 | Updated 2025-02-20 | Assigner palo_alto


MEDIUM: 6.8CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/AU:Y/R:U/V:D/U:Amber

Problem types

CWE-754 Improper Check for Unusual or Exceptional Conditions

Product status

Default status
unaffected

8.3-CE before 8.3.101-CE
affected

8.4.0
affected

8.5.0 before 8.5.1
affected

8.6.0
unaffected

Timeline

2025-02-12:Initial Publication

Credits

Eldar Aharoni of Palo Alto Networks finder

References

security.paloaltonetworks.com/CVE-2025-0112 vendor-advisory

cve.org (CVE-2025-0112)

nvd.nist.gov (CVE-2025-0112)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-0112

Support options

Helpdesk Chat, Email, Knowledgebase
MonTueWedThuFriSatSun
311234567891011121314151617181920212223242526272829301234567891011
MonTueWedThuFriSatSun
311234567891011121314151617181920212223242526272829301234567891011