PT-2021-15585 · Mcafee · Mcafee Endpoint Security (Ens) For Windows

Alain Rödel

·

Published

2021-02-10

·

Updated

2023-11-16

·

CVE-2021-23883

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: McAfee Endpoint Security (ENS) for Windows versions prior to 10.7.0 February 2021 Update
Description: A Null Pointer Dereference issue allows a local administrator to cause Windows to crash via a specific system call which is not handled correctly. This varies by machine and had partial protection prior to the update.
Recommendations: For versions prior to 10.7.0 February 2021 Update, update to the February 2021 Update or later to resolve the issue. As a temporary workaround, consider restricting system calls to minimize the risk of exploitation.

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2021-23883

Affected Products

Mcafee Endpoint Security (Ens) For Windows