CVE-2020-1984: Palo Alto Networks Secdo

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Secdo tries to execute a script at a hardcoded path if present, which allows a local authenticated user with 'create folders or append data' access to the root of the OS disk (C:\) to gain system privileges if the path does not already exist or is writable. This issue affects all versions of Secdo for Windows.

Affected products

Published 2020-04-08. Last modified 2026-06-17.