Insecure DLL loading in Cortex XDR Agent for Windows - CVE-2021-3041
Published: June 9, 2021
Cortex XDR Agent for Windows
Palo Alto Networks, Inc.
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to the application loads DLL libraries in an insecure manner. A local user with privileges to create files in the Windows root directory or to manipulate key registry values and execute arbitrary code on the system with SYSTEM privileges.