Cortex XDR Agent: Exceptional condition denial-of-service (DoS)
Vulnerability Description
An improper handling of exceptional conditions vulnerability in Cortex XDR Agent allows a local authenticated Windows user to create files in the software's internal program directory that prevents the Cortex XDR Agent from starting. The exceptional condition is persistent and prevents Cortex XDR Agent from starting when the software or machine is restarted. This issue impacts: Cortex XDR Agent 5.0 versions earlier than 5.0.10; Cortex XDR Agent 6.1 versions earlier than 6.1.7; Cortex XDR Agent 7.0 versions earlier than 7.0.3; Cortex XDR Agent 7.1 versions earlier than 7.1.2.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-2020
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Palo Alto Networks thanks Paul van der Haas of Orange Cyberdefense for discovering and reporting this issue.
More from Palo Alto Networks
View All →Affected Vendor
Palo Alto Networks
View all reports →