7.8
CVE-2020-7280
- EPSS 0.4%
- Veröffentlicht 10.06.2020 12:15:11
- Zuletzt bearbeitet 21.11.2024 05:36:58
- Erkennungen
Symbolic Link vulnerability during DAT update
Privilege Escalation vulnerability during daily DAT updates when using McAfee Virus Scan Enterprise (VSE) prior to 8.8 Patch 15 allows local users to cause the deletion and creation of files they would not normally have permission to through altering the target of symbolic links. This is timing dependent.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mcafee ≫ Virusscan Enterprise Version 8.8 Update - SwPlatform windows
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch1 SwPlatform windows
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch10 SwPlatform windows
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch11 SwPlatform windows
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch12 SwPlatform windows
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch13 SwPlatform windows
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch14 SwPlatform windows
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch2 SwPlatform windows
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch3 SwPlatform windows
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch4 SwPlatform windows
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch5 SwPlatform windows
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch6 SwPlatform windows
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch7 SwPlatform windows
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch8 SwPlatform windows
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch9 SwPlatform windows
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.4% | 0.316 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
| Trellix | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
https://kc.mcafee.com/corporate/index?page=content&id=SB10302
https://www.zerodayinitiative.com/advisories/ZDI-20-702/