PT-2019-5514 · Mcafee · Mcafee Virusscan Enterprise

Glenn Lloyd

·

Publicado

2019-12-27

·

Atualizado

2020-06-17

·

CVE-2020-7280

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions McAfee VirusScan Enterprise versions prior to 8.8 Patch 15
Description The issue is related to insufficient access control in McAfee VirusScan Enterprise, which can be exploited to elevate privileges. This can occur during daily DAT updates, allowing local users to delete and create files they would not normally have permission to access by altering the target of symbolic links. This exploit is timing-dependent.
Recommendations For versions prior to 8.8 Patch 15, update to 8.8 Patch 15 or later to resolve the issue. As a temporary workaround, consider restricting access to the symbolic links that can be altered during the daily DAT updates until a patch is applied.

Correção

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-03432
CVE-2020-7280
ZDI-20-702

Produtos afetados

Mcafee Virusscan Enterprise