Error handling in Cortex XDR Agent for Windows - CVE-2020-2020

 

Error handling in Cortex XDR Agent for Windows - CVE-2020-2020

Published: December 9, 2020 / Updated: December 10, 2020


Vulnerability identifier: #VU48909
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-2020
CWE-ID: CWE-388
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient handling of exceptional conditions in in Cortex XDR Agent. A local user can create files in the software's internal program directory that prevents the Cortex XDR Agent from starting when the software or machine is restarted.


Affected software

Cortex XDR Agent for Windows

How to mitigate CVE-2020-2020

Install updates from vendor's website.

Cortex XDR Agent for Windows - addressed in versions 5.0.10, 6.1.7, 7.0.3, 7.1.2

External References

Related Security Bulletins