HIGH
Privilege Escalation vulnerability in McAfee Total Protection (MTP)
Published Dec 1, 2020
7.8
HIGHCVSS 3.1
EPSS 0.43%
Description
Privilege Escalation vulnerability in Microsoft Windows client McAfee Total Protection (MTP) prior to 16.0.29 allows local users to gain elevated privileges via careful manipulation of a folder by creating a junction link. This exploits a lack of protection through a timing issue and is only exploitable in a small time window.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<=16.0.29
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| McAfee,LLC | McAfee Total Protection (MTP) | n/a |
|
- < 16.0.29
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- http://service.mcafee.com/FAQDocument.aspx?&id=TS103089 x_refsource_CONFIRM
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-28462 Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-1388/ x_refsource_MISC
| Link | Providers | Tags |
|---|---|---|
| http://service.mcafee.com/FAQDocument.aspx?&id=TS103089 | x_refsource_CONFIRM | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-28462 | Advisory | |
| https://www.zerodayinitiative.com/advisories/ZDI-20-1388/ | x_refsource_MISC |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner trellix
Published Dec 1, 2020
Updated Aug 4, 2024
Reserved Jan 21, 2020
Link CVE-2020-7335
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2020-28462 Assigner trellix
Published Dec 1, 2020
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2020-28462