PT-2020-19563 · Mcafee · Mcafee Application/Change Control

Published

2020-10-15

·

Updated

2020-10-21

·

CVE-2020-7334

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions McAfee Application and Change Control (MACC) versions prior to 8.3.2
Description The issue allows local administrators to change or update configuration settings via a carefully constructed MSI that mimics the genuine installer. This is due to an improper privilege assignment vulnerability in the installer. The vulnerability enables local administrators to modify settings by creating a specially crafted MSI file.
Recommendations For versions prior to 8.3.2, update to version 8.3.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the installer to prevent local administrators from exploiting the vulnerability.

Fix

Incorrect Privilege Assignment

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-7334

Affected Products

Mcafee Application/Change Control