Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Secdo: Privilege escalation via hardcoded script path
Vulnerability Description
Secdo tries to execute a script at a hardcoded path if present, which allows a local authenticated user with 'create folders or append data' access to the root of the OS disk (C:\) to gain system privileges if the path does not already exist or is writable. This issue affects all versions of Secdo for Windows.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
文件名或路径的外部可控制
Vulnerability Title
Palo Alto Networks Secdo 输入验证错误漏洞
Vulnerability Description
Palo Alto Networks Secdo是美国Palo Alto Networks公司的一套安全事件响应解决方案。 Palo Alto Networks Secdo中存在输入验证错误漏洞,该漏洞源于Secdo在硬编码路径上执行脚本。本地攻击者可通过在OS磁盘(C:)的根目录中创建文件夹或添加数据利用该漏洞获得系统权限。
CVSS Information
N/A
Vulnerability Type
N/A