Vulnerability Description
Secdo tries to execute a script at a hardcoded path if present, which allows a local authenticated user with 'create folders or append data' access to the root of the OS disk (C:\) to gain system privileges if the path does not already exist or is writable. This issue affects all versions of Secdo for Windows.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Paloaltonetworks | Secdo | All versions |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://security.paloaltonetworks.com/CVE-2020-1984Vendor Advisory
- https://security.paloaltonetworks.com/CVE-2020-1984Vendor Advisory
FAQ
What is CVE-2020-1984?
CVE-2020-1984 is a vulnerability with a CVSS score of 7.8 (HIGH). Secdo tries to execute a script at a hardcoded path if present, which allows a local authenticated user with 'create folders or append data' access to the root of the OS disk (C:\) to gain system priv...
How severe is CVE-2020-1984?
CVE-2020-1984 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-1984?
Check the references section above for vendor advisories and patch information. Affected products include: Paloaltonetworks Secdo, Microsoft Windows.