PT-2020-19509 · Mcafee · Mcafee Endpoint Security (Ens) For Windows
Published
2020-04-01
·
Updated
2022-06-02
·
CVE-2020-7263
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
McAfee Endpoint Security (ENS) for Windows (affected versions not specified)
Description
The issue is related to an improper access control vulnerability in ESconfigTool.exe, which allows a local administrator to alter the ENS configuration, potentially disabling all protection offered by ENS. This is due to the insecure implementation of encryption for configuration export and import.
Recommendations
For all current versions of McAfee Endpoint Security (ENS) for Windows, consider restricting access to the ESconfigTool.exe to prevent unauthorized configuration changes until a proper fix is implemented.
As a temporary workaround, limit the privileges of local administrators to minimize the risk of exploitation.
Avoid using the insecurely implemented encryption for configuration export and import in ESconfigTool.exe until the issue is resolved.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mcafee Endpoint Security (Ens) For Windows