CVE-2020-7323 MEDIUM

CVE-2020-7323: Authentication Protection Bypass vulnerability in ENS for Windows

Vendor Mcafee Llc
Product Endpoint Security for Windows
Weakness CWE-287 · Improper authentication
Published September 9, 2020
Last update September 17, 2024

CVSS base score

6.9/10
Attack vector Physical
Attack complexity High
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L

What the vulnerability does

01Description

Authentication Protection Bypass vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows physical local users to bypass the Windows lock screen via triggering certain detection events while the computer screen is locked and the McTray.exe is running with elevated privileges. This issue is timing dependent and requires physical access to the machine.

Key dates

02Disclosure timeline

September 9, 2020 CVE published
September 17, 2024 Record updated