s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

CVE-2022-0025 medium

📛 Threat Title

Cortex XDR Agent: An Uncontrolled Search Path Element Leads to Local Privilege Escalation (PE) Vulnerability

Category: vulnerability Published: Source updated: First seen: Last updated: Source: Paloalto Networks Security

Description

A local privilege escalation (PE) vulnerability exists in Palo Alto Networks Cortex XDR agent software on Windows that enables an authenticated local user with file creation privilege in the Windows r...

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

cve CVE-2022-0025

IOC database

Type
cve
Value
CVE-2022-0025
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Cortex XDR Agent: An Uncontrolled Search Path Element Leads to Local Privilege Escalation (PE) Vulnerability

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • Palo Alto Networks advisory: CVE-2022-0025 Paloalto Networks Security

    A local privilege escalation (PE) vulnerability exists in Palo Alto Networks Cortex XDR agent software on Windows that enables an authenticated local user with file creation privilege in the Windows r...

Remediations (8)

  • web:krebsonsecurity.com

    Microsoft this week pushed security updates to fix more than 60 vulnerabilities in its Windows operating systems and supported software, including at least one zero-day bug that is already being ...

  • web:nvd.nist.gov

    Vulnerabilities All vulnerabilities in the NVD have been assigned a CVE identifier and thus, abide by the definition below. CVE defines a vulnerability as: "A weakness in the computational logic (e.g., code) found in software and hardware components that, when exploited, results in a negative impact to confidentiality, integrity, or availability. Mitigation of the vulnerabilities in this ...

  • web:portal.msrc.microsoft.com

    The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

  • web:www.askvg.com

    In this article, we'll discuss about all known and resolved issues present in the latest Windows 11 2025 Update (version 25H2) operating system. Windows 11 25H2 is a new feature update for Windows 11 operating system that adds many new features and improvements to the OS as well as fixes lots of bug and issues reported by the users. But there are some known issues in this feature update ...

  • web:www.helpnetsecurity.com

    September 2025 Patch Tuesday is now live: Microsoft, Adobe, SAP deliver critical fixes for September 2025 Patch Tuesday We work in an industry driven by Common Vulnerabilities and Exposures ( CVE ).

  • web:www.manageengine.com

    Unfold what this Patch Tuesday has in store for you Patch Tuesday, the unofficial term for Microsoft's scheduled security fix release on every second Tuesday of a month, has been a constant topic of discussion ever since its inception. Upcoming Webinar May 14,2026 11:30 EDT & 6:30 a.m. GMT Agenda of the Free Patch Tuesday webinar A complete breakdown of all the latest Patch Tuesday updates ...

  • web:www.oracle.com

    This Critical Patch Update contains 374 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at October 2025 Critical Patch Update: Executive Summary and Analysis.

  • web:www.ultimatewindowssecurity.com

    How to Detect Pass-the-Hash Attacks Blog Series Come meet Randy in Orlando at Microsoft Ignite at Quest's Booth #1818 Detecting Pass-the-Hash with Honeypots Catch Malware Hiding in WMI with Sysmon For of all sad words of tongue or pen, the saddest are these: 'We weren't logging' Experimenting with Windows Security: Controls for Enforcing Policies Sysmon Event IDs 1, 6, 7 Report All the ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.