Bypass Record

Disable or Modify Tools × Palo Alto Networks Cortex XDR Agent

A publicly-reported instance of Disable or Modify Tools bypassing Palo Alto Networks Cortex XDR Agent, recorded with its original source. Factual record; no assessment of any specific deployment.

Product
Palo Alto Networks Cortex XDR Agent
Technique
Disable or Modify Tools
MITRE ATT&CK
T1562.001
Confidence
High
Severity
High
Status
patched
Disclosed
2024-06-12
Config / version noted
Not stated

Provenance

Reported as

CVE-2024-9469 allows a low-privileged user to disable the agent by manipulating CPU usage checks

Mechanism

CVE-2024-5907: The Cortex XDR agent's support file generation creates a predictable temporary folder in C:\Windows\Temp with weak ACLs. By placing a junction (NTFS soft link) in that folder pointing to a target directory, an attacker can force the SYSTEM-level cyserver.exe process to delete arbitrary files/folders during cleanup. Combined with a Windows Installer race condition, this can lead to privilege escalation. CVE-2024-9469: The agent's Adaptive Policy module monitors CPU usage to auto-disable protection under high load. A low-privileged user can artificially inflate CPU usage of the agent's processes, triggering the auto-disable mechanism and turning off all protections.

Detection & mitigation

Monitor for unexpected termination or suspension of Cortex XDR agent processes (e.g., cyserver.exe) and changes to agent configuration or protection status via Windows Event Logs (Security/System) and EDR telemetry. Mitigate by applying vendor patches, restricting local administrative privileges, and hardening file system permissions on temporary folders used by the agent.

Disable or Modify Tools has also been recorded against

This is a record of a publicly-reported event, not an assessment of any specific organization's deployment. Detection and mitigation notes are drawn from the cited source. Where the source is silent, fields are omitted.