CVE-2020-7255 LOW

CVE-2020-7255: Privilege Escalation vulnerability  in ENS

Vendor Mcafee Llc
Product McAfee Endpoint Security (ENS)
Weakness CWE-264
Published April 15, 2020
Last update September 16, 2024

CVSS base score

3.9/10
Attack vector Local
Attack complexity High
Privileges required Low
User interaction Required
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:L

What the vulnerability does

01Description

Privilege escalation vulnerability in the administrative user interface in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2020 Update allows local users to gain elevated privileges via ENS not checking user permissions when editing configuration in the ENS client interface. Administrators can lock the ENS client interface through ePO to prevent users being able to edit the configuration.

Key dates

02Disclosure timeline

April 15, 2020 CVE published
September 16, 2024 Record updated