Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-7280


Privilege Escalation vulnerability during daily DAT updates when using McAfee Virus Scan Enterprise (VSE) prior to 8.8 Patch 15 allows local users to cause the deletion and creation of files they would not normally have permission to through altering the target of symbolic links. This is timing dependent.


Published

2020-06-10T12:15:11.493

Last Modified

2024-11-21T05:36:58.820

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.9

Impact Score

6.4

Weaknesses
  • Type: Secondary
    CWE-269
  • Type: Primary
    CWE-269

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mcafee virusscan_enterprise 8.8 Yes
Application mcafee virusscan_enterprise 8.8 Yes
Application mcafee virusscan_enterprise 8.8 Yes
Application mcafee virusscan_enterprise 8.8 Yes
Application mcafee virusscan_enterprise 8.8 Yes
Application mcafee virusscan_enterprise 8.8 Yes
Application mcafee virusscan_enterprise 8.8 Yes
Application mcafee virusscan_enterprise 8.8 Yes
Application mcafee virusscan_enterprise 8.8 Yes
Application mcafee virusscan_enterprise 8.8 Yes
Application mcafee virusscan_enterprise 8.8 Yes
Application mcafee virusscan_enterprise 8.8 Yes
Application mcafee virusscan_enterprise 8.8 Yes
Application mcafee virusscan_enterprise 8.8 Yes
Application mcafee virusscan_enterprise 8.8 Yes

References