CVE-2020-1984

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
08/04/2020
Last modified:
10/04/2020

Description

Secdo tries to execute a script at a hardcoded path if present, which allows a local authenticated user with 'create folders or append data' access to the root of the OS disk (C:\) to gain system privileges if the path does not already exist or is writable. This issue affects all versions of Secdo for Windows.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:paloaltonetworks:secdo:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools