Privilege Escalation vulnerability in MA for Windows
CVE-2020-7311

7.8HIGH

Key Information:

Vendor

Mcafee Llc

Vendor
CVE Published:
10 September 2020

What is CVE-2020-7311?

Privilege Escalation vulnerability in the installer in McAfee Agent (MA) for Windows prior to 5.6.6 allows local users to assume SYSTEM rights during the installation of MA via manipulation of log files.

Affected Version(s)

MA for Windows 5.6.x < 5.6.6

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

McAfee credits Sebastian Schuster from Airbus CyberSecurity for responsibly reporting this flaw.
.