Vulnerability Description
An insecure temporary file vulnerability in Palo Alto Networks Traps allows a local authenticated Windows user to escalate privileges or overwrite system files. This issue affects Palo Alto Networks Traps 5.0 versions before 5.0.8; 6.1 versions before 6.1.4 on Windows. This issue does not affect Cortex XDR 7.0. This issue does not affect Traps for Linux or MacOS.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Paloaltonetworks | Traps | >= 5.0, < 5.0.8 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://security.paloaltonetworks.com/CVE-2020-1991Vendor Advisory
- https://security.paloaltonetworks.com/CVE-2020-1991Vendor Advisory
FAQ
What is CVE-2020-1991?
CVE-2020-1991 is a vulnerability with a CVSS score of 7.8 (HIGH). An insecure temporary file vulnerability in Palo Alto Networks Traps allows a local authenticated Windows user to escalate privileges or overwrite system files. This issue affects Palo Alto Networks T...
How severe is CVE-2020-1991?
CVE-2020-1991 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-1991?
Check the references section above for vendor advisories and patch information. Affected products include: Paloaltonetworks Traps, Microsoft Windows.