First published: Thu Oct 15 2020(Updated: )
Improperly implemented security check in McAfee Active Response (MAR) prior to 2.4.4 may allow local administrators to execute malicious code via stopping a core Windows service leaving McAfee core trust component in an inconsistent state resulting in MAR failing open rather than closed
Credit: psirt@mcafee.com
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Active Response | <2.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-7326 is a vulnerability in McAfee Active Response (MAR) prior to 2.4.4 that allows local administrators to execute malicious code by stopping a core Windows service.
CVE-2020-7326 has a severity keyword of medium and a severity value of 6.7.
Local administrators can exploit CVE-2020-7326 by stopping a core Windows service, which leaves the McAfee core trust component in an inconsistent state.
McAfee Active Response versions prior to 2.4.4 are affected by CVE-2020-7326.
To fix CVE-2020-7326, upgrade McAfee Active Response to version 2.4.4 or higher.