PT-2020-5577 · Mcafee · Mcafee Endpoint Security

Published

2020-04-15

·

Updated

2020-04-20

·

CVE-2020-7259

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions McAfee Endpoint Security versions prior to 10.7.0 February 2020 Update
Description The issue is related to the exploitation of a Privilege/Trust vulnerability in McAfee Endpoint Security, which allows local users to bypass local security protection. This can be achieved via a carefully crafted input file. The vulnerability is associated with insecure privilege management, enabling an attacker to circumvent existing security restrictions using a specially formed file.
Recommendations For versions prior to 10.7.0 February 2020 Update, update to the February 2020 Update or a later version to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation. Avoid using specially crafted input files that could be used to bypass security protection until the issue is resolved.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01197
CVE-2020-7259

Affected Products

Mcafee Endpoint Security