Vulnerabilities > CVE-2020-7251 - Incorrect Authorization vulnerability in Mcafee Endpoint Security
Attack vector
LOCAL Attack complexity
LOW Privileges required
LOW Confidentiality impact
NONE Integrity impact
HIGH Availability impact
NONE Summary
Improper access control vulnerability in Configuration Tool in McAfee Mcafee Endpoint Security (ENS) Prior to 10.6.1 February 2020 Update allows local users to disable security features via unauthorised use of the configuration tool from older versions of ENS.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Nessus
NASL family | Windows |
NASL id | MCAFEE_ENS_SB10299.NASL |
description | The version of the McAfee Endpoint Security (ENS) for Windows installed on the remote Windows host is 10.5.x prior to 10.5.5 October 2019 Update, 10.6.x prior to 10.6.1 February 2020 Update, or 10.7.x prior to 10.7.0 February 2020 Update. It is, therefore, affected by multiple vulnerabilities: - Code Injection vulnerability in EPSetup.exe in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 2019 Update allows local user to get their malicious code installed by the ENS installer via code injection into EPSetup.exe by an attacker with access to the installer. (CVE-2019-3652) - Improper access control vulnerability in Configuration tool in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 2019 Update allows local user to gain access to security configuration via unauthorized use of the configuration tool. (CVE-2019-3653) - Improper access control vulnerability in configuration tool in McAfee Endpoint Security (ENS) prior to 10.6.1 February 2020 Update allows local user to disable security features via unauthorized use of the configuration tool from older versions of ENS. (CVE-2020-7251) |
last seen | 2020-04-30 |
modified | 2019-10-25 |
plugin id | 130271 |
published | 2019-10-25 |
reporter | This script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/130271 |
title | McAfee Endpoint Security for Windows 10.5.x < 10.5.5 October 2019 Update / 10.6.x < 10.6.1 February 2020 Update / 10.7.x < 10.7.0 February 2020 Update Multiple Vulnerabilities (SB10299) |
code |
|