CVE-2020-7264: Privilege Escalation vulnerability through symbolic links in ENS for Windows
Privilege Escalation vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 Hotfix 199847 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file. This is achieved through running a malicious script or program on the target machine.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7264?
CVE-2020-7264 is a Privilege Escalation vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 Hotfix 199847.
How does CVE-2020-7264 affect McAfee Endpoint Security?
CVE-2020-7264 allows local users to delete files they would not have access to by manipulating symbolic links to redirect a McAfee delete action to an unintended file.
What is the severity of CVE-2020-7264?
CVE-2020-7264 has a severity rating of 8.4 (high).
Which versions of McAfee Endpoint Security are affected by CVE-2020-7264?
CVE-2020-7264 affects McAfee Endpoint Security versions prior to 10.7.0 Hotfix 199847.
How can the Privilege Escalation vulnerability in McAfee Endpoint Security be fixed?
To fix the Privilege Escalation vulnerability in McAfee Endpoint Security, update to version 10.7.0 Hotfix 199847 or later.