Privilege escalation in Advanced Threat Defense
CVE-2020-7254

7.7HIGH

Key Information:

Vendor
Mcafee, Llc
Status
Mcafee Advanced Threat Defense (atd)
Vendor
CVE Published:
12 March 2020

Summary

Privilege Escalation vulnerability in the command line interface in McAfee Advanced Threat Defense (ATD) 4.x prior to 4.8.2 allows local users to execute arbitrary code via improper access controls on the sudo command.

Affected Version(s)

McAfee Advanced Threat Defense (ATD) 4.x < 4.8.2

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

McAfee credits Jerome Nokin from NCIA for responsibly reporting CVE-2020-7254
.