PT-2020-19563 · Mcafee · Mcafee Application/Change Control
Published
2020-10-15
·
Updated
2020-10-21
·
CVE-2020-7334
CVSS v3.1
8.2
High
| Vector | AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
McAfee Application and Change Control (MACC) versions prior to 8.3.2
Description
The issue allows local administrators to change or update configuration settings via a carefully constructed MSI that mimics the genuine installer. This is due to an improper privilege assignment vulnerability in the installer. The vulnerability enables local administrators to modify settings by creating a specially crafted MSI file.
Recommendations
For versions prior to 8.3.2, update to version 8.3.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the installer to prevent local administrators from exploiting the vulnerability.
Fix
Incorrect Privilege Assignment
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mcafee Application/Change Control