CVE-2020-7287: Privilege Escalation vulnerability in EDR for Linux
Published May 8, 2020
·Updated
Privilege Escalation vulnerability in McAfee Exploit Detection and Response (EDR) for Linux prior to 3.1.0 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been granted access to.
Affected Software
3 affected components
McAfee Endpoint Detection And Response<3.1.0
McAfee Endpoint Detection And Response=3.1.0
Linux Linux kernel
Event History
May 8, 2020
CVE Published
via MITRE·12:40 PM
Data Sourced
via MITRE·12:40 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-7287?
CVE-2020-7287 has a medium severity rating, indicating significant risk of privilege escalation.
2
How do I fix CVE-2020-7287?
To mitigate CVE-2020-7287, upgrade to McAfee Endpoint Detection and Response version 3.1.0 Hotfix 1 or later.
3
What software is affected by CVE-2020-7287?
CVE-2020-7287 affects McAfee Endpoint Detection and Response versions earlier than 3.1.0 Hotfix 1.
4
What type of vulnerability is CVE-2020-7287?
CVE-2020-7287 is classified as a privilege escalation vulnerability.
5
Can CVE-2020-7287 be exploited remotely?
CVE-2020-7287 requires local access to exploit, as it leverages the permissions of the current user.