Vulnerabilities > Mcafee

DATE CVE VULNERABILITY TITLE RISK
2021-02-10 CVE-2021-23873 Link Following vulnerability in Mcafee Total Protection
Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and perform arbitrary file deletion as the SYSTEM user potentially causing Denial of Service via manipulating Junction link, after enumerating certain files, at a specific time.
local
low complexity
mcafee CWE-59
6.1
2021-02-10 CVE-2021-23883 NULL Pointer Dereference vulnerability in Mcafee Endpoint Security
A Null Pointer Dereference vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update allows a local administrator to cause Windows to crash via a specific system call which is not handled correctly.
local
low complexity
mcafee CWE-476
4.4
2021-02-10 CVE-2021-23882 Unspecified vulnerability in Mcafee Endpoint Security
Improper Access Control vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update allows local administrators to prevent the installation of some ENS files by placing carefully crafted files where ENS will be installed.
local
low complexity
mcafee
4.4
2021-02-10 CVE-2021-23880 Unspecified vulnerability in Mcafee Endpoint Security
Improper Access Control in attribute in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update allows authenticated local administrator user to perform an uninstallation of the anti-malware engine via the running of a specific command with the correct parameters.
local
low complexity
mcafee
4.4
2021-02-10 CVE-2021-23878 Cleartext Storage of Sensitive Information vulnerability in Mcafee Endpoint Security
Clear text storage of sensitive Information in memory vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update allows a local user to view ENS settings and credentials via accessing process memory after the ENS administrator has performed specific actions.
local
low complexity
mcafee CWE-312
5.0
2021-01-26 CVE-2021-3156 Off-by-one Error vulnerability in multiple products
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
7.8
2021-01-20 CVE-2021-1257 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
A vulnerability in the web-based management interface of Cisco DNA Center Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to manipulate an authenticated user into executing malicious actions without their awareness or consent.
network
low complexity
cisco mcafee CWE-352
8.8
2021-01-18 CVE-2020-7343 Missing Authorization vulnerability in Mcafee Agent
Missing Authorization vulnerability in McAfee Agent (MA) for Windows prior to 5.7.1 allows local users to block McAfee product updates by manipulating a directory used by MA for temporary files.
local
low complexity
mcafee CWE-862
5.5
2021-01-13 CVE-2021-1258 Improper Privilege Management vulnerability in multiple products
A vulnerability in the upgrade component of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker with low privileges to read arbitrary files on the underlying operating system (OS) of an affected device.
local
low complexity
cisco mcafee CWE-269
5.5
2021-01-05 CVE-2020-7336 Cross-Site Request Forgery (CSRF) vulnerability in Mcafee Network Security Management 10.0/10.1.7.7/9.0
Cross Site Request Forgery vulnerability in McAfee Network Security Management (NSM) prior to 10.1.7.35 and NSM 9.x prior to 9.2.9.55 may allow an attacker to change the configuration of the Network Security Manager via a carefully crafted HTTP request.
network
low complexity
mcafee CWE-352
6.5