An unprivileged user can delete arbitrary files on a Linux system running ENSLTP 10.5.1, 10.5.0, and 10.2.3 Hotfix 1246778 and earlier. By exploiting a time of check to time of use (TOCTOU) race condition during a specific scanning sequence, the unprivileged user is able to perform a privilege escalation to delete arbitrary files.
2018-09-18T21:29:04.183
2024-11-21T04:11:06.833
Modified
CVSSv3.1: 5.3 (MEDIUM)
AV:L/AC:M/Au:N/C:N/I:P/A:P
3.4
4.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | mcafee | endpoint_security_for_linux_threat_prevention | ≤ 10.2.3 | Yes |
| Application | mcafee | endpoint_security_for_linux_threat_prevention | 10.5.1 | Yes |
| Application | mcafee | endpoint_security_linux_threat_prevention | 10.5.0 | Yes |
| Operating System | linux | linux_kernel | - | No |