CVE-2019-3652: ENS code injection in EPSetup.exe
Code Injection vulnerability in EPSetup.exe in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 2019 Update allows local user to get their malicious code installed by the ENS installer via code injection into EPSetup.exe by an attacker with access to the installer.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-3652?
CVE-2019-3652 is a code injection vulnerability in EPSetup.exe in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 2019 Update.
How does CVE-2019-3652 impact users?
CVE-2019-3652 allows a local user to install malicious code using the ENS installer via code injection into EPSetup.exe.
Which version of McAfee Endpoint Security is affected by CVE-2019-3652?
CVE-2019-3652 affects McAfee Endpoint Security versions between 10.5.0 and 10.5.5, and versions between 10.6.0 and 10.6.1.
How severe is CVE-2019-3652?
CVE-2019-3652 has a severity score of 5.3 (medium).
How can I fix CVE-2019-3652?
To fix CVE-2019-3652, users should update McAfee Endpoint Security to version 10.6.1 or later.