Privilege escalation in Advanced Threat Defense
CVE-2020-7254
7.7HIGH
Key Information:
- Vendor
- Mcafee, Llc
- Status
- Mcafee Advanced Threat Defense (atd)
- Vendor
- CVE Published:
- 12 March 2020
Summary
Privilege Escalation vulnerability in the command line interface in McAfee Advanced Threat Defense (ATD) 4.x prior to 4.8.2 allows local users to execute arbitrary code via improper access controls on the sudo command.
Affected Version(s)
McAfee Advanced Threat Defense (ATD) 4.x < 4.8.2
References
CVSS V3.1
Score:
7.7
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
McAfee credits Jerome Nokin from NCIA for responsibly reporting CVE-2020-7254