A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent. This issue may be leveraged by malware to perform malicious activity without detection.
Update Palo Alto Networks/Cortex XDR Agent to 9.0.1 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanCortex XDR Agent: Local Administrator can disable the agent on Windows affects Palo Alto Networks/Cortex XDR Agent (generic). Severity is medium. A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent. This issue may be leveraged by malware to perform malicious activity without detection.
AI coding agents often install or upgrade packages automatically in generic. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Palo Alto Networks/Cortex XDR Agentgeneric | >=9.0 <9.0.1 || >=8.9 <8.9.1 || >=8.7-CE <8.7.101-CE || >=8.3-CE <8.3-CE-CU-2120 || >=7.9-CE <7.9-CE-CU-2120 | 9.0.1, 8.9.1, 8.7.101-CE, 8.3-CE-CU-2120, 7.9-CE-CU-2120 |
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent. This issue may be leveraged by malware to perform malicious activity without detection.
Update Palo Alto Networks/Cortex XDR Agent to 9.0.1 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanCortex XDR Agent: Local Administrator can disable the agent on Windows affects Palo Alto Networks/Cortex XDR Agent (generic). Severity is medium. A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent. This issue may be leveraged by malware to perform malicious activity without detection.
AI coding agents often install or upgrade packages automatically in generic. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Palo Alto Networks/Cortex XDR Agentgeneric | >=9.0 <9.0.1 || >=8.9 <8.9.1 || >=8.7-CE <8.7.101-CE || >=8.3-CE <8.3-CE-CU-2120 || >=7.9-CE <7.9-CE-CU-2120 | 9.0.1, 8.9.1, 8.7.101-CE, 8.3-CE-CU-2120, 7.9-CE-CU-2120 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL GuardFixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard