CVE-2020-7263

Improper access control vulnerability in ESconfigTool.exe in McAfee Endpoint Security (ENS) for Windows all current versions allows local administrator to alter ENS configuration up to and including disabling all protection offered by ENS via insecurely implemented encryption of configuration for export and import.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mcafee:endpoint_security:10.5.0:*:*:*:*:windows:*:*
cpe:2.3:a:mcafee:endpoint_security:10.5.1:*:*:*:*:windows:*:*
cpe:2.3:a:mcafee:endpoint_security:10.5.2:*:*:*:*:windows:*:*
cpe:2.3:a:mcafee:endpoint_security:10.5.3:*:*:*:*:windows:*:*
cpe:2.3:a:mcafee:endpoint_security:10.5.4:*:*:*:*:windows:*:*
cpe:2.3:a:mcafee:endpoint_security:10.5.5:*:*:*:*:windows:*:*
cpe:2.3:a:mcafee:endpoint_security:10.6.0:*:*:*:*:windows:*:*
cpe:2.3:a:mcafee:endpoint_security:10.6.1:*:*:*:*:windows:*:*
cpe:2.3:a:mcafee:endpoint_security:10.7.0:*:*:*:*:windows:*:*

History

21 Nov 2024, 05:36

Type Values Removed Values Added
CVSS v2 : 4.6
v3 : 6.7
v2 : 4.6
v3 : 6.5
References () https://kc.mcafee.com/corporate/index?page=content&id=SB10314 - () https://kc.mcafee.com/corporate/index?page=content&id=SB10314 -

07 Nov 2023, 03:25

Type Values Removed Values Added
References (CONFIRM) https://kc.mcafee.com/corporate/index?page=content&id=SB10314 - Mitigation, Patch, Vendor Advisory () https://kc.mcafee.com/corporate/index?page=content&id=SB10314 -

Information

Published : 2020-04-01 07:15

Updated : 2024-11-21 05:36


NVD link : CVE-2020-7263

Mitre link : CVE-2020-7263

CVE.ORG link : CVE-2020-7263


JSON object : View

Products Affected

mcafee

  • endpoint_security
CWE
CWE-264

Permissions, Privileges, and Access Controls

CWE-732

Incorrect Permission Assignment for Critical Resource