7.8

CVE-2020-7279

DLL search order hijacking in Host IPS

DLL Search Order Hijacking Vulnerability in the installer component of McAfee Host Intrusion Prevention System (Host IPS) for Windows prior to 8.0.0 Patch 15 Update allows attackers with local access to execute arbitrary code via execution from a compromised folder.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mcafee ≫ Host Intrusion Prevention Version 8.0.0 Update - SwPlatform windows
Mcafee ≫ Host Intrusion Prevention Version 8.0.0 Update p1 SwPlatform windows
Mcafee ≫ Host Intrusion Prevention Version 8.0.0 Update p10 SwPlatform windows
Mcafee ≫ Host Intrusion Prevention Version 8.0.0 Update p11 SwPlatform windows
Mcafee ≫ Host Intrusion Prevention Version 8.0.0 Update p12 SwPlatform windows
Mcafee ≫ Host Intrusion Prevention Version 8.0.0 Update p13 SwPlatform windows
Mcafee ≫ Host Intrusion Prevention Version 8.0.0 Update p14 SwPlatform windows
Mcafee ≫ Host Intrusion Prevention Version 8.0.0 Update p15 SwPlatform windows
Mcafee ≫ Host Intrusion Prevention Version 8.0.0 Update p2 SwPlatform windows
Mcafee ≫ Host Intrusion Prevention Version 8.0.0 Update p3 SwPlatform windows
Mcafee ≫ Host Intrusion Prevention Version 8.0.0 Update p4 SwPlatform windows
Mcafee ≫ Host Intrusion Prevention Version 8.0.0 Update p5 SwPlatform windows
Mcafee ≫ Host Intrusion Prevention Version 8.0.0 Update p6 SwPlatform windows
Mcafee ≫ Host Intrusion Prevention Version 8.0.0 Update p7 SwPlatform windows
Mcafee ≫ Host Intrusion Prevention Version 8.0.0 Update p8 SwPlatform windows
Mcafee ≫ Host Intrusion Prevention Version 8.0.0 Update p9 SwPlatform windows
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.41% 0.321
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 4.4 3.4 6.4
AV:L/AC:M/Au:N/C:P/I:P/A:P
Trellix 4.6 0.3 4.2
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:H/A:N
CWE-426 Untrusted Search Path

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

https://kc.mcafee.com/corporate/index?page=content&id=SB10320