CVE-2020-7288: Privilege Escalation vulnerability in EDR for Mac
Published May 8, 2020
·Updated
Privilege Escalation vulnerability in McAfee Exploit Detection and Response (EDR) for Mac prior to 3.1.0 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been granted access to.
Affected Software
3 affected components
McAfee Endpoint Detection And Response<3.1.0
McAfee Endpoint Detection And Response=3.1.0
Apple macOS
Event History
May 7, 2020
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-7288?
CVE-2020-7288 is classified as a privilege escalation vulnerability.
2
How do I fix CVE-2020-7288?
To address CVE-2020-7288, upgrade to McAfee Exploit Detection and Response for Mac version 3.1.0 Hotfix 1 or later.
3
What products are affected by CVE-2020-7288?
CVE-2020-7288 affects McAfee Endpoint Detection and Response for versions prior to 3.1.0 Hotfix 1.
4
Can CVE-2020-7288 allow unauthorized actions?
Yes, CVE-2020-7288 enables a malicious script or program to perform unauthorized functions.
5
Is macOS itself vulnerable to CVE-2020-7288?
No, macOS is not directly vulnerable, but the installed McAfee EDR on macOS is affected.