Improper Authorization vulnerability in MA
CVE-2020-7343
5.5MEDIUM
Key Information:
- Vendor
- Mcafee, Llc
- Status
- Mcafee Agent
- Vendor
- CVE Published:
- 18 January 2021
Summary
Missing Authorization vulnerability in McAfee Agent (MA) for Windows prior to 5.7.1 allows local users to block McAfee product updates by manipulating a directory used by MA for temporary files. The product would continue to function with out-of-date detection files.
Affected Version(s)
McAfee Agent 5.7.x < 5.7.1
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
McAfee credits Andrew Hess (any1) for responsibly reporting this flaw.