Vulnerabilities > Mcafee > Endpoint Security

DATE CVE VULNERABILITY TITLE RISK
2020-11-12 CVE-2020-7331 Unquoted Search Path or Element vulnerability in Mcafee Endpoint Security
Unquoted service executable path in McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update allows local users to cause a denial of service and malicious file execution via carefully crafted and named executable files.
local
low complexity
mcafee CWE-428
7.8
2020-09-09 CVE-2020-7323 Improper Authentication vulnerability in Mcafee Endpoint Security
Authentication Protection Bypass vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows physical local users to bypass the Windows lock screen via triggering certain detection events while the computer screen is locked and the McTray.exe is running with elevated privileges.
high complexity
mcafee CWE-287
6.9
2020-09-09 CVE-2020-7322 Information Exposure Through Log Files vulnerability in Mcafee Endpoint Security
Information Disclosure Vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local users to gain access to sensitive information via incorrectly logging of sensitive information in debug logs.
local
high complexity
mcafee CWE-532
4.7
2020-09-09 CVE-2020-7320 Unspecified vulnerability in Mcafee Endpoint Security
Protection Mechanism Failure vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local administrator to temporarily reduce the detection capability allowing otherwise detected malware to run via stopping certain Microsoft services.
local
low complexity
mcafee
7.3
2020-09-09 CVE-2020-7319 Link Following vulnerability in Mcafee Endpoint Security
Improper Access Control vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local users to access files which the user otherwise would not have access to via manipulating symbolic links to redirect McAfee file operations to an unintended file.
local
low complexity
mcafee CWE-59
8.8
2020-05-08 CVE-2020-7265 Improper Privilege Management vulnerability in Mcafee Endpoint Security
Privilege Escalation vulnerability in McAfee Endpoint Security (ENS) for Mac prior to 10.6.9 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file.
local
low complexity
mcafee CWE-269
8.4
2020-05-08 CVE-2020-7264 Improper Privilege Management vulnerability in Mcafee Endpoint Security
Privilege Escalation vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 Hotfix 199847 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file.
local
low complexity
mcafee CWE-269
8.4
2020-04-15 CVE-2020-7255 Improper Privilege Management vulnerability in Mcafee Endpoint Security
Privilege escalation vulnerability in the administrative user interface in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2020 Update allows local users to gain elevated privileges via ENS not checking user permissions when editing configuration in the ENS client interface.
local
low complexity
mcafee CWE-269
4.4
2020-04-15 CVE-2020-7250 Link Following vulnerability in Mcafee Endpoint Security
Symbolic link manipulation vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2020 Update allows authenticated local user to potentially gain an escalation of privileges by pointing the link to files which the user which not normally have permission to alter via carefully creating symbolic links from the ENS log file directory.
local
low complexity
mcafee CWE-59
7.8
2020-04-15 CVE-2020-7277 Unspecified vulnerability in Mcafee Endpoint Security
Protection mechanism failure in all processes in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 April 2020 Update allows local users to stop certain McAfee ENS processes, reducing the protection offered.
local
low complexity
mcafee
5.3