First published: Wed Apr 08 2020(Updated: )
Improper input validation vulnerability in Secdo allows an authenticated local user with 'create folders or append data' access to the root of the OS disk (C:\) to cause a system crash on every login. This issue affects all versions Secdo for Windows.
Credit: psirt@paloaltonetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Paloaltonetworks Secdo | ||
Microsoft Windows |
This product is no longer supported and the issue will not be fixed. This issue can be easily mitigated by creating a "C:\proc" folder and not allowing unprivileged users to access to that folder, or ensuring unprivileged users do not have 'create folder' access to the root of a disk (C:\).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.