5.9
CVE-2014-9920
- EPSS 0.4%
- Published 14.03.2017 22:59:00
- Last modified 20.04.2025 01:37:25
- Source secure@intel.com
- Teams watchlist Login
- Open Login
Unauthorized execution of binary vulnerability in McAfee (now Intel Security) McAfee Application Control (MAC) 6.0.0 before hotfix 9726, 6.0.1 before hotfix 9068, 6.1.0 before hotfix 692, 6.1.1 before hotfix 399, 6.1.2 before hotfix 426, and 6.1.3 before hotfix 357 and earlier allows attackers to create a malformed Windows binary that is considered non-executable and is not protected through the whitelisting protection feature via a specific set of circumstances.
Data is provided by the National Vulnerability Database (NVD)
Mcafee ≫ Application Control Version6.0.0
Mcafee ≫ Application Control Version6.0.1
Mcafee ≫ Application Control Version6.1.0
Mcafee ≫ Application Control Version6.1.1
Mcafee ≫ Application Control Version6.1.2
Mcafee ≫ Application Control Version6.1.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.4% | 0.577 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5.9 | 2.2 | 3.6 |
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.