6.7
CVE-2020-7337
- EPSS 0.41%
- Veröffentlicht 09.12.2020 09:15:13
- Zuletzt bearbeitet 21.11.2024 05:37:05
- Erkennungen
Incorrect Permission Assignment for Critical Resource
Incorrect Permission Assignment for Critical Resource vulnerability in McAfee VirusScan Enterprise (VSE) prior to 8.8 Patch 16 allows local administrators to bypass local security protection through VSE not correctly integrating with Windows Defender Application Control via careful manipulation of the Code Integrity checks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mcafee ≫ Virusscan Enterprise Version < 8.8
Mcafee ≫ Virusscan Enterprise Version 8.8 Update -
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch1
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch10
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch11
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch12
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch13
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch14
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch15
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch2
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch3
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch4
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch5
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch6
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch7
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch8
Mcafee ≫ Virusscan Enterprise Version 8.8 Update patch9
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.41% | 0.323 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
| Trellix | 6.5 | 0.6 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
|
CWE-732 Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
https://kc.mcafee.com/corporate/index?page=content&id=SB10338