Autorun registry bypass
CVE-2020-7273

6.7MEDIUM

Key Information:

Vendor
Mcafee Llc
Status
Mcafee Endpoint Security (ens)
Vendor
CVE Published:
15 April 2020

Summary

Accessing functionality not properly constrained by ACLs vulnerability in the autorun start-up protection in McAfee Endpoint Security (ENS) for Windows Prior to 10.7.0 April 2020 Update allows local users to delete or rename programs in the autorun key via manipulation of some parameters.

Affected Version(s)

McAfee Endpoint Security (ENS) 10.x < 10.7.0 April 2020 Update

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

McAfee credits Dávid Müller for reporting this flaw
.