Unrestricted Policy Management using MfeUpgradeTool.exe
CVE-2020-7276
6.4MEDIUM
Key Information:
- Vendor
- Mcafee Llc
- Status
- Mcafee Endpoint Security (ens)
- Vendor
- CVE Published:
- 15 April 2020
Summary
Authentication bypass vulnerability in MfeUpgradeTool in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 April 2020 Update allows administrator users to access policy settings via running this tool.
Affected Version(s)
McAfee Endpoint Security (ENS) 10.x < 10.7.0 April 2020 Update
References
CVSS V3.1
Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved