MEDIUM
Buffer overwrite in ENS allowed to bypass AMSI protection
Published Apr 15, 2020
6.1
MEDIUMCVSS 3.1
EPSS 0.26%
Description
Buffer Overflow via Environment Variables vulnerability in AMSI component in McAfee Endpoint Security (ENS) Prior to 10.7.0 February 2020 Update allows local users to disable Endpoint Security via a carefully crafted user input.
Affected products
-
- Version 10.xStatusaffectedConstraints<10.7.0 April 2020 Update
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| McAfee LLC | McAfee Endpoint Security (ENS) | n/a |
|
OR
- 10.5.0
- 10.5.1
- 10.5.2
- 10.5.3
- 10.5.4
- 10.5.5
- 10.6.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (1)
- https://kc.mcafee.com/corporate/index?page=content&id=SB10309 x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://kc.mcafee.com/corporate/index?page=content&id=SB10309 | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner trellix
Published Apr 15, 2020
Updated Sep 16, 2024
Reserved Jan 21, 2020
Link CVE-2020-7261
CISA Vulnrichment
Updated n/a