CVE-2020-7255

Privilege escalation vulnerability in the administrative user interface in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2020 Update allows local users to gain elevated privileges via ENS not checking user permissions when editing configuration in the ENS client interface. Administrators can lock the ENS client interface through ePO to prevent users being able to edit the configuration.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mcafee:endpoint_security:10.5.0:*:*:*:*:windows:*:*
cpe:2.3:a:mcafee:endpoint_security:10.5.1:*:*:*:*:windows:*:*
cpe:2.3:a:mcafee:endpoint_security:10.5.2:*:*:*:*:windows:*:*
cpe:2.3:a:mcafee:endpoint_security:10.5.3:*:*:*:*:windows:*:*
cpe:2.3:a:mcafee:endpoint_security:10.5.4:*:*:*:*:windows:*:*
cpe:2.3:a:mcafee:endpoint_security:10.5.5:*:*:*:*:windows:*:*
cpe:2.3:a:mcafee:endpoint_security:10.6.0:*:*:*:*:windows:*:*

History

21 Nov 2024, 05:36

Type Values Removed Values Added
References () https://kc.mcafee.com/corporate/index?page=content&id=SB10309 - () https://kc.mcafee.com/corporate/index?page=content&id=SB10309 -
CVSS v2 : 3.6
v3 : 4.4
v2 : 3.6
v3 : 3.9

07 Nov 2023, 03:25

Type Values Removed Values Added
References (CONFIRM) https://kc.mcafee.com/corporate/index?page=content&id=SB10309 - Vendor Advisory () https://kc.mcafee.com/corporate/index?page=content&id=SB10309 -

Information

Published : 2020-04-15 13:15

Updated : 2024-11-21 05:36


NVD link : CVE-2020-7255

Mitre link : CVE-2020-7255

CVE.ORG link : CVE-2020-7255


JSON object : View

Products Affected

mcafee

  • endpoint_security
CWE
CWE-264

Permissions, Privileges, and Access Controls

CWE-269

Improper Privilege Management