PT-2020-5326 · Mcafee · Mcafee File/Removable Media Protection

Published

2020-10-07

·

Updated

2020-10-16

·

CVE-2020-7316

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions McAfee File and Removable Media Protection versions prior to 5.3.0
Description The issue is related to an unquoted service path in McAfee File and Removable Media Protection, which can be exploited to allow a local user to execute arbitrary code with higher privileges. This can be achieved by executing from a compromised folder, potentially resulting in files not being encrypted when a policy is triggered.
Recommendations For versions prior to 5.3.0, update to version 5.3.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the service path to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-00104
CVE-2020-7316

Affected Products

Mcafee File/Removable Media Protection