7
CVE-2020-7311
- EPSS 0.28%
- Veröffentlicht 10.09.2020 10:15:10
- Zuletzt bearbeitet 21.11.2024 05:37:02
- Erkennungen
Privilege Escalation vulnerability in MA for Windows
Privilege Escalation vulnerability in the installer in McAfee Agent (MA) for Windows prior to 5.6.6 allows local users to assume SYSTEM rights during the installation of MA via manipulation of log files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mcafee ≫ Mcafee Agent SwPlatform windows Version < 5.6.6
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.28% | 0.194 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7 | 1 | 5.9 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 6.9 | 3.4 | 10 |
AV:L/AC:M/Au:N/C:C/I:C/A:C
|
| Trellix | 7.8 | 1.1 | 6 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
https://kc.mcafee.com/corporate/index?page=content&id=SB10325