Unsigned executable vulnerability in ENS can be used to bypass intended self-protection rules
CVE-2020-7259

6.6MEDIUM

Key Information:

Vendor
Mcafee Llc
Status
Mcafee Endpoint Security (ens)
Vendor
CVE Published:
15 April 2020

Summary

Exploitation of Privilege/Trust vulnerability in file in McAfee Endpoint Security (ENS) Prior to 10.7.0 February 2020 Update allows local users to bypass local security protection via a carefully crafted input file

Affected Version(s)

McAfee Endpoint Security (ENS) 10.x < 10.7.0 April 2020 Update

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.