#VU26735 External Control of File Name or Path in Secdo - CVE-2020-1984
Published: April 9, 2020
Secdo
Palo Alto Networks, Inc.
Description
The vulnerability allows a local user to escalate privileges on the target system.
Thevulnerability exists due to the affected software tries to execute a script at a hardcoded path if present. A local user with "create folders or append data" access to the root of the OS disk (C:\) can gain system privileges if the path does not already exist or is writable.