s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

CVE-2022-0014 medium

📛 Threat Title

Cortex XDR Agent: Unintended Program Execution When Using Live Terminal Session

Category: vulnerability Published: Source updated: First seen: Last updated: Source: Paloalto Networks Security

Description

An untrusted search path vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables a local attacker with file creation privilege in the Windows root directory (such as C:\) to store...

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

cve CVE-2022-0014

IOC database

Type
cve
Value
CVE-2022-0014
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Cortex XDR Agent: Unintended Program Execution When Using Live Terminal Session

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • Palo Alto Networks advisory: CVE-2022-0014 Paloalto Networks Security

    An untrusted search path vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables a local attacker with file creation privilege in the Windows root directory (such as C:\) to store...

Remediations (8)

  • web:access.redhat.com

    Learn about our open source products, services, and company. You are here

  • web:attack.mitre.org

    This mitigation can be implemented through the following measures: Regular Operating System Updates Implementation: Apply the latest Windows security updates monthly using WSUS (Windows Server Update Services) or a similar patch management solution. Configure systems to check for updates automatically and schedule reboots during maintenance ...

  • web:nvd.nist.gov

    The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics. For ...

  • web:portal.msrc.microsoft.com

    The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

  • web:www.cisa.gov

    Organizations across both public and private sectors struggle to find time to test and implement remediations to these vulnerabilities—such as patches and updates—across complex infrastructures. Additionally, the effort and subject matter expertise required to research the degree of risk posed by a given vulnerability makes prioritizing CVEs a challenge.

  • web:www.mdpi.com

    Nevertheless, these studies typically emphasize either detection (often source-code focused) or patch management at a process level, and they rarely synthesize detection and mitigation together under a single PRISMA-governed protocol while also foregrounding modern trends such as LLM-assisted remediation and DRL-based dynamic prioritization.

  • web:www.rapid7.com

    Microsoft is publishing 66 new vulnerabilities today, which is far fewer than we've come to expect in recent months. However, the lone zero-day vulnerability this month demands attention.

  • web:www.tenable.com

    Mitigation Summary - Vulnerabilities by CVE ID: This matrix presents vulnerability summary information by Common Vulnerabilities and Exposures ( CVE ) identifier. The CVE system is a dictionary of publicly known information security vulnerabilities and exposures in publicly released software packages.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.