6.7
CVE-2020-7315
- EPSS 0.1%
- Veröffentlicht 10.09.2020 10:15:11
- Zuletzt bearbeitet 21.11.2024 05:37:02
- Quelle trellixpsirt@trellix.com
- CVE-Watchlists
- Unerledigt
DLL Injection vulnerability in MA for Windows
DLL Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.6.6 allows local users to execute arbitrary code via careful placement of a malicious DLL.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mcafee ≫ Mcafee Agent SwPlatformwindows Version < 5.6.6
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.1% | 0.284 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
| trellixpsirt@trellix.com | 6 | 0.8 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
|
CWE-426 Untrusted Search Path
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.