CVE-2020-7276: Unrestricted Policy Management using MfeUpgradeTool.exe
Authentication bypass vulnerability in MfeUpgradeTool in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 April 2020 Update allows administrator users to access policy settings via running this tool.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-7276?
The severity of CVE-2020-7276 is medium with a severity value of 6.7.
How does CVE-2020-7276 impact McAfee Endpoint Security?
CVE-2020-7276 allows administrator users to access policy settings via running the MfeUpgradeTool in McAfee Endpoint Security versions prior to 10.7.0 April 2020 Update.
Which versions of McAfee Endpoint Security are affected by CVE-2020-7276?
CVE-2020-7276 affects McAfee Endpoint Security versions 10.5.0, 10.5.1, 10.5.2, 10.5.3, 10.5.4, 10.5.5, and 10.6.0.
How can I fix CVE-2020-7276?
To fix CVE-2020-7276, it is recommended to update McAfee Endpoint Security to version 10.7.0 April 2020 Update or later.
Where can I find more information about CVE-2020-7276?
More information about CVE-2020-7276 can be found at the following reference: https://kc.mcafee.com/corporate/index?page=content&id=SB10309