
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability was discovered in Palo Alto Networks Traps that allows a local authenticated Windows user to escalate privileges or overwrite system files. This issue affects Traps versions 5.0 before 5.0.8, 6.1 before 6.1.4 on Windows, and all versions of 6.0, 4.2, 4.1, and older releases on Windows. The vulnerability does not affect Cortex XDR 7.0 or Traps for Linux and MacOS (Palo Alto).
The vulnerability is classified as an insecure temporary file vulnerability with a CVSSv3.1 Base Score of 7.8 (HIGH) and vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. The weakness type is identified as CWE-377 Insecure Temporary File (Palo Alto).
If exploited, this vulnerability allows an authenticated local Windows user to escalate privileges or overwrite system files, potentially compromising the security of the affected system (Palo Alto).
The vulnerability requires local access and low privileges to exploit. No user interaction is needed for exploitation, making it relatively straightforward to exploit once local access is obtained (Palo Alto).
The issue has been fixed in Traps versions 5.0.8, 6.1.4, and later versions. There are no viable workarounds for this vulnerability, making it critical for affected users to update to the patched versions (Palo Alto).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."