PT-2020-19520 · Mcafee · Mcafee Endpoint Security (Ens) For Windows
Published
2020-04-15
·
Updated
2020-04-20
·
CVE-2020-7278
CVSS v3.1
7.4
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
McAfee Endpoint Security (ENS) for Windows versions prior to 10.7.0
McAfee Endpoint Security (ENS) for Windows versions prior to 10.6.1 April 2020
Description
Exploiting incorrectly configured access control security levels vulnerability in ENS Firewall allows remote attackers and local users to allow or block unauthorized traffic via pre-existing rules not being handled correctly when updating to the February 2020 updates.
Recommendations
For versions prior to 10.7.0, update to version 10.7.0 or later.
For versions prior to 10.6.1 April 2020, update to 10.6.1 April 2020 or later.
Fix
Improper Access Control
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mcafee Endpoint Security (Ens) For Windows