First published: Wed Apr 15 2020(Updated: )
Authentication bypass vulnerability in MfeUpgradeTool in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 April 2020 Update allows administrator users to access policy settings via running this tool.
Credit: psirt@mcafee.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mcafee Endpoint Security | =10.5.0 | |
Mcafee Endpoint Security | =10.5.1 | |
Mcafee Endpoint Security | =10.5.2 | |
Mcafee Endpoint Security | =10.5.3 | |
Mcafee Endpoint Security | =10.5.4 | |
Mcafee Endpoint Security | =10.5.5 | |
Mcafee Endpoint Security | =10.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-7276 is medium with a severity value of 6.7.
CVE-2020-7276 allows administrator users to access policy settings via running the MfeUpgradeTool in McAfee Endpoint Security versions prior to 10.7.0 April 2020 Update.
CVE-2020-7276 affects McAfee Endpoint Security versions 10.5.0, 10.5.1, 10.5.2, 10.5.3, 10.5.4, 10.5.5, and 10.6.0.
To fix CVE-2020-7276, it is recommended to update McAfee Endpoint Security to version 10.7.0 April 2020 Update or later.
More information about CVE-2020-7276 can be found at the following reference: https://kc.mcafee.com/corporate/index?page=content&id=SB10309