First published: Fri May 08 2020(Updated: )
Privilege Escalation vulnerability in McAfee VirusScan Enterprise (VSE) for Windows prior to 8.8 Patch 14 Hotfix 116778 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file. This is achieved through running a malicious script or program on the target machine.
Credit: psirt@mcafee.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mcafee Virusscan Enterprise | >=1.9.0<1.9.2 | |
Mcafee Virusscan Enterprise | >=2.0.0<2.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-7266.
The severity of CVE-2020-7266 is high with a CVSS score of 8.4.
The vulnerability allows local users to delete files they would otherwise not have access to by manipulating symbolic links.
Versions 1.9.0 to 1.9.2 and versions 2.0.0 to 2.0.3 of McAfee VirusScan Enterprise for Linux are affected.
To fix this vulnerability, update to McAfee VirusScan Enterprise for Windows 8.8 Patch 14 Hotfix 116778 or later.