Wednesday, 09 July 2025

Palo Alto Networks Patches Flaws in Prisma Cloud Compute, Cortex XDR Agent

Palo Alto Networks announced the availability of patches for security flaws in the Prisma Cloud Compute cloud protection solution and the Cortex XDR platform.

The most serious of the bugs -- CVE-2021-3042 -- is a local privilege escalation (PE) issue in the Palo Alto Networks Cortex XDR agent on Windows platforms. The flaw carries a CVSS score of 7.8.

According to Palo Alto Networks, the issue could be exploited by authenticated attackers with local access that have file creation privilege in the Windows root directory. Successful exploitation could lead to the attacker executing programs with SYSTEM privileges.

The second vulnerability -- CVE-2021-3043 (CVSS score of 7.5) -- is a reflected cross-site scripting (XSS) vulnerability that affects the Prisma Cloud Compute web console. A remote attacker able to exploit this vulnerability could execute arbitrary JavaScript code. The fixes were automatically applied to Prisma Cloud Compute SaaS installations.

Source: securityweek.com

28 July 2021

-
104