ESConfig Tool access not controlled
CVE-2019-3653

4.6MEDIUM

Key Information:

Vendor
Mcafee, Llc
Status
Mcafee Endpoint Security (ens)
Vendor
CVE Published:
9 October 2019

Summary

Improper access control vulnerability in Configuration tool in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 2019 Update allows local user to gain access to security configuration via unauthorized use of the configuration tool.

Affected Version(s)

McAfee Endpoint Security (ENS) 10.6.x < 10.6.1

McAfee Endpoint Security (ENS) 10.5.x < 10.5.5

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.