← Back

CVE-2020-2049

nvd nist
Published: Dec 9, 2020Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: psirt@paloaltonetworks.com (Secondary)

Description

A local privilege escalation vulnerability exists in Palo Alto Networks Cortex XDR Agent on the Windows platform that allows an authenticated local Windows user to execute programs with SYSTEM privileges. This requires the user to have the privilege to create files in the Windows root directory. This issue impacts: All versions of Cortex XDR Agent 7.1 with content update 149 and earlier versions; All versions of Cortex XDR Agent 7.2 with content update 149 and earlier versions.

Affected (6)

Cortex Xdr Agent
Configuration A
6 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Paloaltonetworks
From 7.1.1 to 7.1.3
From 7.2.1 to 7.2.2
Version 7.1
Version 7.1 content_update149
Version 7.2
Version 7.2 content_update149
Running on/withPlatform Versions
Microsoft
Windows
All versions

References (2)

Source: psirt@paloaltonetworks.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.