First published: Wed Apr 08 2020(Updated: )
Incorrect Default Permissions on C:\Programdata\Secdo\Logs folder in Secdo allows local authenticated users to overwrite system files and gain escalated privileges. This issue affects all versions Secdo for Windows.
Credit: psirt@paloaltonetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Paloaltonetworks Secdo | ||
Microsoft Windows |
This product is no longer supported and the issue will not be fixed. Change permission on C:\Programdata\Secdo\Logs folder to not allow unprivileged users access.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-1985 has a high severity rating due to its potential for local authenticated users to gain escalated privileges.
To fix CVE-2020-1985, ensure that the permissions on the C:\Programdata\Secdo\Logs folder are configured correctly to prevent unauthorized access.
All versions of Secdo for Windows are affected by CVE-2020-1985.
CVE-2020-1985 is classified as an incorrect default permissions vulnerability.
CVE-2020-1985 cannot be exploited remotely as it requires local authenticated access.