6.9
CVE-2019-3588
- EPSS 0.28%
- Veröffentlicht 10.06.2020 12:15:11
- Zuletzt bearbeitet 21.11.2024 04:42:13
- Erkennungen
Using VSE to bypass Windows Credentials on Lock screen
Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 14 may allow unauthorized users to interact with the On-Access Scan Messages - Threat Alert Window when the Windows Login Screen is locked.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mcafee ≫ Virusscan Enterprise Version 8.8 Update - SwPlatform windows
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch1 SwPlatform windows
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch10 SwPlatform windows
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch11 SwPlatform windows
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch12 SwPlatform windows
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch13 SwPlatform windows
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch2 SwPlatform windows
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch3 SwPlatform windows
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch4 SwPlatform windows
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch5 SwPlatform windows
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch6 SwPlatform windows
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch7 SwPlatform windows
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch8 SwPlatform windows
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch9 SwPlatform windows
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.28% | 0.193 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.8 | 0.9 | 5.9 |
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 6.9 | 3.4 | 10 |
AV:L/AC:M/Au:N/C:C/I:C/A:C
|
| Trellix | 6.3 | 0.4 | 5.9 |
CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
https://kc.mcafee.com/corporate/index?page=content&id=SB10302