Unrestricted Policy Management using MfeUpgradeTool.exe
CVE-2020-7276

6.4MEDIUM

Key Information:

Vendor
Mcafee Llc
Status
Mcafee Endpoint Security (ens)
Vendor
CVE Published:
15 April 2020

Summary

Authentication bypass vulnerability in MfeUpgradeTool in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 April 2020 Update allows administrator users to access policy settings via running this tool.

Affected Version(s)

McAfee Endpoint Security (ENS) 10.x < 10.7.0 April 2020 Update

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.