MEDIUM
Autorun registry bypass
Published Apr 15, 2020
6.7
MEDIUMCVSS 3.1
EPSS 0.25%
Description
Accessing functionality not properly constrained by ACLs vulnerability in the autorun start-up protection in McAfee Endpoint Security (ENS) for Windows Prior to 10.7.0 April 2020 Update allows local users to delete or rename programs in the autorun key via manipulation of some parameters.
Affected products
-
Affected
- ≥ 10.x, < 10.7.0 April 2020 Update
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| McAfee LLC | McAfee Endpoint Security (ENS) | unknown | Affected
|
OR
- 10.5.0
- 10.5.1
- 10.5.2
- 10.5.3
- 10.5.4
- 10.5.5
- 10.6.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-28400 Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10309 x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-28400 | Advisory | |
| https://kc.mcafee.com/corporate/index?page=content&id=SB10309 | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner trellix
Published Apr 15, 2020
Updated Sep 16, 2024
Reserved Jan 21, 2020
Link CVE-2020-7273
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data