CVE-2020-7312: DLL Search Order Hijacking in MA for Windows
Published Sep 10, 2020
·Updated
DLL Search Order Hijacking Vulnerability in the installer in McAfee Agent (MA) for Windows prior to 5.6.6 allows local users to execute arbitrary code and escalate privileges via execution from a compromised folder.
Affected Software
1 affected component
McAfee Mcafee Agent Windows<5.6.6
Event History
Sep 10, 2020
CVE Published
via MITRE·09:45 AM
Data Sourced
via MITRE·09:45 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this DLL Search Order Hijacking vulnerability?
The vulnerability ID for this DLL Search Order Hijacking vulnerability is CVE-2020-7312.
2
What is the severity rating of CVE-2020-7312?
CVE-2020-7312 has a severity rating of 7.8 (High).
3
Which software is affected by CVE-2020-7312?
The software affected by CVE-2020-7312 is McAfee Agent (MA) for Windows prior to version 5.6.6.
4
How can local users exploit CVE-2020-7312?
Local users can exploit CVE-2020-7312 by executing arbitrary code and escalating privileges from a compromised folder.
5
How can I fix CVE-2020-7312?
To fix CVE-2020-7312, update to McAfee Agent version 5.6.6 or later.