Autorun registry bypass
CVE-2020-7273
6.7MEDIUM
Key Information:
- Vendor
- Mcafee Llc
- Status
- Mcafee Endpoint Security (ens)
- Vendor
- CVE Published:
- 15 April 2020
Summary
Accessing functionality not properly constrained by ACLs vulnerability in the autorun start-up protection in McAfee Endpoint Security (ENS) for Windows Prior to 10.7.0 April 2020 Update allows local users to delete or rename programs in the autorun key via manipulation of some parameters.
Affected Version(s)
McAfee Endpoint Security (ENS) 10.x < 10.7.0 April 2020 Update
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
McAfee credits Dávid Müller for reporting this flaw