CVE-2024-5907: Palo Alto Networks Cortex Xdr Agent
High severity, CVSS 7.0. EPSS: 0.1% chance of exploitation in the next 30 days.
A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices enables a local user to execute programs with elevated privileges. However, execution does require the local user to successfully exploit a race condition, which makes this vulnerability difficult to exploit.
Affected products
- Palo Alto Networks Cortex Xdr Agent: from 7.9, before 7.9.102 (fixed in 7.9.102); from 8.1, before 8.2.3 (fixed in 8.2.3); from 8.3, before 8.3.1 (fixed in 8.3.1)
Published 2024-06-12. Last modified 2026-06-17.