CVE-2019-3653: ESConfig Tool access not controlled
Improper access control vulnerability in Configuration tool in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 2019 Update allows local user to gain access to security configuration via unauthorized use of the configuration tool.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-3653?
CVE-2019-3653 is an improper access control vulnerability in the Configuration tool in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 2019 Update.
How does CVE-2019-3653 work?
CVE-2019-3653 allows a local user to gain access to security configuration by unauthorized use of the configuration tool.
What software is affected by CVE-2019-3653?
McAfee Endpoint Security versions prior to 10.6.1 October 2019 Update and 10.16.1 are affected by CVE-2019-3653.
What is the severity of CVE-2019-3653?
CVE-2019-3653 has a severity rating of 5.5 (Medium).
How can I fix CVE-2019-3653?
To fix CVE-2019-3653, users should update to McAfee Endpoint Security version 10.6.1 October 2019 Update or later.