=====================================================================

                               CERT-Renater

                     Note d'Information No. 2023/VULN324

_____________________________________________________________________

DATE                : 14/09/2023

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Cortex XDR agent versions prior
                               to 8.0.2, 7.9.101-CE, 7.9.3.

=====================================================================
https://securityadvisories.paloaltonetworks.com/CVE-2023-3280
_____________________________________________________________________

Palo Alto Networks Security Advisories / CVE-2023-3280

CVE-2023-3280 Cortex XDR Agent: Local Windows User Can Disable the
Agent


047910
Severity 5.5 . MEDIUM
Attack Vector LOCAL
Scope UNCHANGED
Attack Complexity LOW
Confidentiality Impact NONE
Privileges Required LOW
Integrity Impact NONE
User Interaction NONE
Availability Impact HIGH
NVD JSON     Published 2023-09-13
Updated 2023-09-13
Reference CPATR-19884
Discovered externally


Description

A problem with a protection mechanism in the Palo Alto Networks
Cortex XDR agent on Windows devices allows a local user to
disable the agent.


Product Status    Versions   Affected          Unaffected
Cortex XDR Agent   8.1       None                   All
Cortex XDR Agent   8.0      < 8.0.2 on Windows      >= 8.0.2
Cortex XDR Agent   7.9-CE   < 7.9.101-CE on Windows >= 7.9.101-CE
Cortex XDR Agent   7.9      < 7.9.3 on Windows      >= 7.9.3
Cortex XDR Agent   7.5-CE   All on Windows
Cortex XDR Agent   5.0      All on Windows


Severity:MEDIUM

CVSSv3.1 Base Score:5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)


Exploitation Status

Palo Alto Networks is not aware of any malicious exploitation of this
issue.


Weakness Type

CWE-755 Improper Handling of Exceptional Conditions


Solution

This issue is fixed in Cortex XDR agent 7.9.101-CE, Cortex XDR agent
7.9.3, Cortex XDR agent 8.0.2, and all later Cortex XDR agent versions.


Acknowledgments

Palo Alto Networks thanks Manuel Feifel of InfoGuard AG for discovering
and reporting this issue.


Timeline

2023-09-13 Initial publication
Terms of usePrivacyProduct Security Assurance and Vulnerability
Disclosure Policy Report vulnerabilitiesManage subscriptions
(C) 2023 Palo Alto Networks, Inc. All rights reserved.


=========================================================
+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================
