McAfee MVEDR - Improperly implemented security check
CVE-2020-7327

6MEDIUM

Key Information:

Vendor
Mcafee,llc
Vendor
CVE Published:
15 October 2020

Summary

Improperly implemented security check in McAfee MVISION Endpoint Detection and Response Client (MVEDR) prior to 3.2.0 may allow local administrators to execute malicious code via stopping a core Windows service leaving McAfee core trust component in an inconsistent state resulting in MVEDR failing open rather than closed

Affected Version(s)

McAfee MVISION Endpoint Detection and Response 3.x < 3.2.0

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.