CVE-2020-2049
Last modified
CVE-2020-2049 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A local privilege escalation vulnerability exists in Palo Alto Networks Cortex XDR Agent on the Windows platform that allows an authenticated local Windows user to execute programs with SYSTEM privileges. This requires the user to have the privilege to create files in the Windows root directory. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
A local privilege escalation vulnerability exists in Palo Alto Networks Cortex XDR Agent on the Windows platform that allows an authenticated local Windows user to execute programs with SYSTEM privileges. This requires the user to have the privilege to create files in the Windows root directory. This issue impacts: All versions of Cortex XDR Agent 7.1 with content update 149 and earlier versions; All versions of Cortex XDR Agent 7.2 with content update 149 and earlier versions.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Paloaltonetworks | Cortex Xdr Agent | >= 7.1.1, <= 7.1.3 |
| Paloaltonetworks | Cortex Xdr Agent | >= 7.2.1, <= 7.2.2 |
| Paloaltonetworks | Cortex Xdr Agent | 7.1 |
| Paloaltonetworks | Cortex Xdr Agent | 7.2 |
References
- https://security.paloaltonetworks.com/CVE-2020-2049Vendor Advisory
- https://security.paloaltonetworks.com/CVE-2020-2049Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-2049?
How severe is CVE-2020-2049?
How do I fix CVE-2020-2049?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-20471White Shark System (WSS) 1.3.2 has an unauthorized access vu…8.8
- CVE-2020-20472White Shark System (WSS) 1.3.2 has a sensitive information d…5.3
- CVE-2020-20473White Shark System (WSS) 1.3.2 has a SQL injection vulnerabi…7.5
- CVE-2020-20474White Shark System (WSS) 1.3.2 has a SQL injection vulnerabi…7.5
- CVE-2020-2048An information exposure through log file vulnerability exist…3.3
- CVE-2020-20486IEC104 v1.0 contains a stack-buffer overflow in the paramete…7.5
- CVE-2020-20490A heap buffer-overflow in the client_example1.c component of…7.5
- CVE-2020-20491SQL injection vulnerability in OpenCart v.2.2.00 thru 3.0.3.…7.2
- CVE-2020-20495bludit v3.13.0 contains an arbitrary file deletion vulnerabi…9.1
- CVE-2020-2050An authentication bypass vulnerability exists in the GlobalP…8.2
- CVE-2020-20502Cross Site Request Forgery found in yzCMS v.2.0 allows a rem…6.5
- CVE-2020-20508Shopkit v2.7 contains a reflective cross-site scripting (XSS…6.1
Are you affected by CVE-2020-2049?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
