CVE-2022-0026
Estado: ModificadaMedia (6.7)—
A local privilege escalation (PE) vulnerability exists in Palo Alto Networks Cortex XDR agent software on Windows that enables an authenticated local user with file creation privilege in the Windows root directory (such as C:\) to execute a program with elevated privileges. This issue impacts all versions of Cortex XDR agent without content update 330 or a later content update version.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 6.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.23%
- Percentil entre todas las CVEs puntuadas: 12
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-282
- NVD-CWE-Other
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-0026",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.2,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@paloaltonetworks.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.7,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 0.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.7,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 0.8
}
]
},
"affected": [
{
"source": "psirt@paloaltonetworks.com",
"affectedData": [
{
"vendor": "Palo Alto Networks",
"product": "Cortex XDR Agent",
"versions": [
{
"status": "affected",
"version": "7.7.* without CU-330"
},
{
"status": "unaffected",
"version": "7.7.* with CU-330"
},
{
"status": "affected",
"version": "7.6.* without CU-330"
},
{
"status": "unaffected",
"version": "7.6.* with CU-330"
},
{
"status": "affected",
"version": "7.5 CE 7.5.* without CU-330"
},
{
"status": "unaffected",
"version": "7.5 CE 7.5.* with CU-330"
},
{
"status": "affected",
"version": "7.4.* without CU-330"
},
{
"status": "unaffected",
"version": "7.4.* with CU-330"
},
{
"status": "affected",
"version": "6.1.* without CU-330"
},
{
"status": "unaffected",
"version": "6.1.* with CU-330"
},
{
"status": "affected",
"version": "7.5.* without CU-330"
},
{
"status": "unaffected",
"version": "7.5.* with CU-330"
}
],
"platforms": [
"Windows"
]
}
]
}
],
"published": "2022-05-11T17:15:09.287",
"references": [
{
"url": "https://security.paloaltonetworks.com/CVE-2022-0026",
"tags": [
"Vendor Advisory"
],
"source": "psirt@paloaltonetworks.com"
},
{
"url": "https://security.paloaltonetworks.com/CVE-2022-0026",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@paloaltonetworks.com",
"description": [
{
"lang": "en",
"value": "CWE-282"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A local privilege escalation (PE) vulnerability exists in Palo Alto Networks Cortex XDR agent software on Windows that enables an authenticated local user with file creation privilege in the Windows root directory (such as C:\\) to execute a program with elevated privileges. This issue impacts all versions of Cortex XDR agent without content update 330 or a later content update version."
},
{
"lang": "es",
"value": "Se presenta una vulnerabilidad de escalada de privilegios (PE) local en el software Cortex XDR agent de Palo Alto Networks en Windows que permite a un usuario local autenticado con privilegios de creación de archivos en el directorio root de Windows (como C:\\) ejecutar un programa con altos privilegios. Este problema afecta a todas las versiones de Cortex XDR agent sin la actualización de contenido 330 o una versión posterior de actualización de contenido"
}
],
"lastModified": "2026-06-17T04:19:54.970",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:6.1:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8535E8E2-188C-460B-86A8-F463854F5DFE"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:6.1:content_update330:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "09A12884-47E6-451E-9751-F871F12692E7"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:6.1.4:content_update330:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "6F522F4D-8740-41C2-A662-2D3FADB98ADB"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:6.1.4:hotfix:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "559A6865-F8E3-4F6B-A53B-5EA48C5B9120"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:6.1.5:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0B027DB3-7A70-443B-B5F4-B66A3BCCF2A6"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:6.1.5:content_update330:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "7103C435-D4CC-46BE-8487-03ADF0135792"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:6.1.5:hotfix:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "14B92689-A030-44F3-9B66-2E003198A407"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:6.1.6:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "920FAB2B-4AEC-48FD-9744-617BC6C494CA"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:6.1.6:content_update330:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4F81B9E1-E1A1-4910-AE0C-65BC8F554A47"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:6.1.7:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2BECB228-650F-448A-931D-DFA7D097E41E"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:6.1.7:content_update330:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1FC042EE-8F41-466C-9D85-556092102EE7"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:6.1.8:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "30B091F7-AE11-4540-A945-7100ACE812AC"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:6.1.8:content_update330:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "5F880FD5-FCC6-4FEE-AB48-088C9C431E64"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:6.1.9:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6792CE52-83C7-4601-B9E5-54FF77103DB0"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:6.1.9:content_update330:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "600E93EA-21E5-41F1-977A-43F0513C2468"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:7.4.1:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5257930C-27F0-4A1E-B5C9-D3D76C27715D"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:7.4.1:content_update330:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "0C01C824-2578-4C11-9578-731B597BECB1"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:7.4.2:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CA4B14D7-5E03-4635-9D75-CEEF0D913EFA"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:7.4.2:content_update330:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "737275AC-C43D-4636-AE0E-BB24A192C525"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:7.4.3:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "799B0C1C-8963-4A04-A3A2-E1D97C6BE467"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:7.4.3:content_update330:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D1221A81-E602-4629-93B8-3ABCA7C1F6C0"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:7.4.4:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "210954DD-8719-4212-8725-3201EF7AF9D1"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:7.4.4:content_update330:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "603A11D1-B95D-48E2-B61C-012B3675D4B7"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:7.5:-:*:*:content_engine:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B6E273B6-A3A4-47EF-9E37-B123B61ECE23"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:7.5.1:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "716232DD-F8C1-43A3-870A-A6C19D7A4416"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:7.5.1:content_update330:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "8E023342-504F-4DF4-8D2F-F824DE72757D"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:7.5.2:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D63504E2-E27A-4714-AB1C-CC67675E47E0"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:7.5.2:content_update330:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "5399BD2D-B6F0-4368-BBAA-D25C3A5B7BAA"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:7.5.3:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D8D5A99A-BB66-4C4D-BFAB-5B07B0A98BAD"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:7.5.3:content_update330:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "42502AD9-5F5E-441C-B32D-FAEDA4D2BBF9"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:7.6.1:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B5D4BBBE-57DE-438A-97B3-29C59EA8C48D"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:7.6.1:content_update330:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "13CBA514-D865-4C9F-A2FE-D2FA3B289DC5"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:7.6.2:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1E4BCC91-31AB-4318-8A1F-D043392F09E2"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:7.6.2:content_update330:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "3E421078-40E0-4D3D-A6A3-825EF9452E99"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:7.7:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EEDE5C5B-48F9-4211-9F98-085C3C5E19FE"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:7.7:content_update330:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A9D89CF1-E2F8-4498-859F-D6FB4F9DC82B"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:7.7.1:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C2927A74-24A5-459B-9D61-2718643F3338"
},
{
"criteria": "cpe:2.3:a:paloaltonetworks:cortex_xdr_agent:7.7.1:content_update330:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "483211AE-3205-4DCD-B602-EE707684C464"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "psirt@paloaltonetworks.com"
}