CVE-2020-7273
Published Apr 15, 2020
Last updated a year ago
Overview
- Description
- Accessing functionality not properly constrained by ACLs vulnerability in the autorun start-up protection in McAfee Endpoint Security (ENS) for Windows Prior to 10.7.0 April 2020 Update allows local users to delete or rename programs in the autorun key via manipulation of some parameters.
- Source
- trellixpsirt@trellix.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 5.5
- Impact score
- 3.6
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 2.1
- Impact score
- 2.9
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:N/I:P/A:N
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:mcafee:endpoint_security:10.5.0:*:*:*:*:windows:*:*", "vulnerable": true, "matchCriteriaId": "6AC514CA-D094-433D-9561-99048D43902F" }, { "criteria": "cpe:2.3:a:mcafee:endpoint_security:10.5.1:*:*:*:*:windows:*:*", "vulnerable": true, "matchCriteriaId": "1B7AE3E9-DDCE-4119-B57D-B3D471E05B16" }, { "criteria": "cpe:2.3:a:mcafee:endpoint_security:10.5.2:*:*:*:*:windows:*:*", "vulnerable": true, "matchCriteriaId": "603FE358-FADA-4FE6-B3F2-169D032A57E9" }, { "criteria": "cpe:2.3:a:mcafee:endpoint_security:10.5.3:*:*:*:*:windows:*:*", "vulnerable": true, "matchCriteriaId": "66461D42-AE21-41B3-9FCB-3F6D09AC323E" }, { "criteria": "cpe:2.3:a:mcafee:endpoint_security:10.5.4:*:*:*:*:windows:*:*", "vulnerable": true, "matchCriteriaId": "DCC441CF-5EA0-41C1-AE15-6672FF20B73A" }, { "criteria": "cpe:2.3:a:mcafee:endpoint_security:10.5.5:*:*:*:*:windows:*:*", "vulnerable": true, "matchCriteriaId": "A6551AB4-1B0F-4EE3-8ED1-99413E3F19DD" }, { "criteria": "cpe:2.3:a:mcafee:endpoint_security:10.6.0:*:*:*:*:windows:*:*", "vulnerable": true, "matchCriteriaId": "94732038-F35D-41AB-A550-E6F5FF9004DF" } ], "operator": "OR" } ] } ]