CVE-2020-7254 HIGH

CVE-2020-7254: Privilege escalation in Advanced Threat Defense

Vendor Mcafee, Llc
Product McAfee Advanced Threat Defense (ATD)
Weakness CWE-264
Published March 12, 2020
Last update September 16, 2024

CVSS base score

7.7/10
Attack vector Local
Attack complexity High
Privileges required Low
User interaction None
Confidentiality Low
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:H

What the vulnerability does

01Description

Privilege Escalation vulnerability in the command line interface in McAfee Advanced Threat Defense (ATD) 4.x prior to 4.8.2 allows local users to execute arbitrary code via improper access controls on the sudo command.

Key dates

02Disclosure timeline

March 12, 2020 CVE published
September 16, 2024 Record updated