Improper privilege assignment vulnerability in the installer component of MACC
CVE-2020-7334
7.7HIGH
Key Information:
- Vendor
- Mcafee,llc
- Status
- Mcafee Application And Change Control (macc)
- Vendor
- CVE Published:
- 15 October 2020
Summary
Improper privilege assignment vulnerability in the installer McAfee Application and Change Control (MACC) prior to 8.3.2 allows local administrators to change or update the configuration settings via a carefully constructed MSI configured to mimic the genuine installer. This version adds further controls for installation/uninstallation of software.
Affected Version(s)
McAfee Application and Change Control (MACC) 8.x < 8.3.2
References
CVSS V3.1
Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved