CVE-2025-0112: Palo Alto Networks Cortex Xdr Agent
Medium severity, CVSS 6.8. EPSS: 0.2% chance of exploitation in the next 30 days.
A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to disable the agent. This vulnerability can also be leveraged by malware to disable the Cortex XDR agent and then perform malicious activity.
Affected products
- Palo Alto Networks Cortex Xdr Agent: from 8.3-CE, before 8.3.101-CE (fixed in 8.3.101-CE); version 8.4.0 only; from 8.5.0, before 8.5.1 (fixed in 8.5.1)
Published 2025-02-20. Last modified 2026-06-17.