Vulnerabilities > Mcafee

DATE CVE VULNERABILITY TITLE RISK
2020-12-01 CVE-2020-7335 Unspecified vulnerability in Mcafee Total Protection
Privilege Escalation vulnerability in Microsoft Windows client McAfee Total Protection (MTP) prior to 16.0.29 allows local users to gain elevated privileges via careful manipulation of a folder by creating a junction link.
local
high complexity
mcafee
7.8
2020-11-12 CVE-2020-7333 Cross-site Scripting vulnerability in Mcafee Endpoint Security
Cross site scripting vulnerability in the firewall ePO extension of McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update allows administrators to inject arbitrary web script or HTML via the configuration wizard.
network
low complexity
mcafee CWE-79
4.8
2020-11-12 CVE-2020-7332 Cross-Site Request Forgery (CSRF) vulnerability in Mcafee Endpoint Security
Cross Site Request Forgery vulnerability in the firewall ePO extension of McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update allows an attacker to execute arbitrary HTML code due to incorrect security configuration.
network
low complexity
mcafee CWE-352
8.8
2020-11-12 CVE-2020-7331 Unquoted Search Path or Element vulnerability in Mcafee Endpoint Security
Unquoted service executable path in McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update allows local users to cause a denial of service and malicious file execution via carefully crafted and named executable files.
local
low complexity
mcafee CWE-428
7.8
2020-11-11 CVE-2020-7329 Server-Side Request Forgery (SSRF) vulnerability in Mcafee Mvision Endpoint
Server-side request forgery vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers trigger server-side DNS requests to arbitrary domains via carefully constructed XML files loaded by an ePO administrator.
network
low complexity
mcafee CWE-918
7.2
2020-11-11 CVE-2020-7328 Server-Side Request Forgery (SSRF) vulnerability in Mcafee Mvision Endpoint
External entity attack vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers to gain control of a resource or trigger arbitrary code execution via improper input validation of an HTTP request, where the content for the attack has been loaded into ePO by an ePO administrator.
network
low complexity
mcafee CWE-918
7.2
2020-10-15 CVE-2020-7327 Authentication Bypass by Spoofing vulnerability in Mcafee Mvision Endpoint Detection and Response 3.0.0/3.1.0
Improperly implemented security check in McAfee MVISION Endpoint Detection and Response Client (MVEDR) prior to 3.2.0 may allow local administrators to execute malicious code via stopping a core Windows service leaving McAfee core trust component in an inconsistent state resulting in MVEDR failing open rather than closed
local
low complexity
mcafee CWE-290
6.7
2020-10-15 CVE-2020-7326 Authentication Bypass by Spoofing vulnerability in Mcafee Active Response
Improperly implemented security check in McAfee Active Response (MAR) prior to 2.4.4 may allow local administrators to execute malicious code via stopping a core Windows service leaving McAfee core trust component in an inconsistent state resulting in MAR failing open rather than closed
local
low complexity
mcafee CWE-290
6.7
2020-10-15 CVE-2020-7334 Improper Privilege Management vulnerability in Mcafee Application and Change Control
Improper privilege assignment vulnerability in the installer McAfee Application and Change Control (MACC) prior to 8.3.2 allows local administrators to change or update the configuration settings via a carefully constructed MSI configured to mimic the genuine installer.
local
low complexity
mcafee CWE-269
8.2
2020-10-14 CVE-2020-7318 Cross-site Scripting vulnerability in Mcafee Epolicy Orchestrator 5.10.0/5.10.9
Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10.9 Update 9 allows administrators to inject arbitrary web script or HTML via multiple parameters where the administrator's entries were not correctly sanitized.
low complexity
mcafee CWE-79
4.3