CVE-2020-1986Medium

CVE-2020-1986 Secdo: Local authenticated users can cause Windows system crash

Published
April 8, 2020
Last Modified
April 8, 2020

🔗 CVE IDs covered (1)

📋 Description

Improper input validation vulnerability in Secdo allows an authenticated local user with 'create folders or append data' access to the root of the OS disk (C:) to cause a system crash on every login. This issue affects all versions Secdo for Windows.

🎯 Affected products1

  • Secdo

✅ Remediation

This product is no longer supported and the issue will not be fixed. This issue can be easily mitigated by creating a "C:\proc" folder and not allowing unprivileged users to access to that folder, or ensuring unprivileged users do not have 'create folder' access to the root of a disk (C:\). Workarounds and mitigations: Exploitation of this issue can be prevented by creating a "C:\proc" folder and not allowing unprivileged users to access that folder.

🔗 References (1)