CVE-2022-0025
medium
📛 Threat Title
Cortex XDR Agent: An Uncontrolled Search Path Element Leads to Local Privilege Escalation (PE) Vulnerability
Description
A local privilege escalation (PE) vulnerability exists in Palo Alto Networks Cortex XDR agent software on Windows that enables an authenticated local user with file creation privilege in the Windows r...
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
cve
CVE-2022-0025
IOC database
- Type
- cve
- Value
CVE-2022-0025- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Cortex XDR Agent: An Uncontrolled Search Path Element Leads to Local Privilege Escalation (PE) Vulnerability
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
Palo Alto Networks advisory: CVE-2022-0025
Paloalto Networks Security
A local privilege escalation (PE) vulnerability exists in Palo Alto Networks Cortex XDR agent software on Windows that enables an authenticated local user with file creation privilege in the Windows r...
Remediations (8)
-
web:krebsonsecurity.com
Microsoft this week pushed security updates to fix more than 60 vulnerabilities in its Windows operating systems and supported software, including at least one zero-day bug that is already being ...
-
web:nvd.nist.gov
Vulnerabilities All vulnerabilities in the NVD have been assigned a CVE identifier and thus, abide by the definition below. CVE defines a vulnerability as: "A weakness in the computational logic (e.g., code) found in software and hardware components that, when exploited, results in a negative impact to confidentiality, integrity, or availability. Mitigation of the vulnerabilities in this ...
-
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
-
web:www.askvg.com
In this article, we'll discuss about all known and resolved issues present in the latest Windows 11 2025 Update (version 25H2) operating system. Windows 11 25H2 is a new feature update for Windows 11 operating system that adds many new features and improvements to the OS as well as fixes lots of bug and issues reported by the users. But there are some known issues in this feature update ...
-
web:www.helpnetsecurity.com
September 2025 Patch Tuesday is now live: Microsoft, Adobe, SAP deliver critical fixes for September 2025 Patch Tuesday We work in an industry driven by Common Vulnerabilities and Exposures ( CVE ).
-
web:www.manageengine.com
Unfold what this Patch Tuesday has in store for you Patch Tuesday, the unofficial term for Microsoft's scheduled security fix release on every second Tuesday of a month, has been a constant topic of discussion ever since its inception. Upcoming Webinar May 14,2026 11:30 EDT & 6:30 a.m. GMT Agenda of the Free Patch Tuesday webinar A complete breakdown of all the latest Patch Tuesday updates ...
-
web:www.oracle.com
This Critical Patch Update contains 374 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at October 2025 Critical Patch Update: Executive Summary and Analysis.
-
web:www.ultimatewindowssecurity.com
How to Detect Pass-the-Hash Attacks Blog Series Come meet Randy in Orlando at Microsoft Ignite at Quest's Booth #1818 Detecting Pass-the-Hash with Honeypots Catch Malware Hiding in WMI with Sysmon For of all sad words of tongue or pen, the saddest are these: 'We weren't logging' Experimenting with Windows Security: Controls for Enforcing Policies Sysmon Event IDs 1, 6, 7 Report All the ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.