Home

Description

A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.

PUBLISHED Reserved 2024-10-03 | Published 2024-10-09 | Updated 2024-10-18 | Assigner palo_alto




MEDIUM: 5.7CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/AU:N/R:U/V:D/RE:M/U:Amber

Problem types

CWE-754: Improper Check for Unusual or Exceptional Conditions

Product status

Default status
unaffected

7.9 (custom) before 7.9.102-CE
affected

8.3 (custom) before 8.3.1
affected

8.3-CE
unaffected

8.4 (custom) before 8.4.1
affected

8.5
unaffected

8.6
unaffected

Timeline

2024-10-09:Initial publication

Credits

Orange Cyberdefense Switzerland's Research Team finder

References

security.paloaltonetworks.com/CVE-2024-9469 vendor-advisory

cve.org (CVE-2024-9469)

nvd.nist.gov (CVE-2024-9469)

Download JSON

Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.