CVE-2020-7331: Unquoted service executable path in McAfee Endpoint Security (ENS)
Unquoted service executable path in McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update allows local users to cause a denial of service and malicious file execution via carefully crafted and named executable files.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7331?
CVE-2020-7331 is a vulnerability in McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update that allows local users to cause a denial of service and execute malicious files.
How does CVE-2020-7331 affect McAfee Endpoint Security?
CVE-2020-7331 affects McAfee Endpoint Security versions prior to 10.7.0 November 2020 Update.
What is the severity of CVE-2020-7331?
CVE-2020-7331 is classified as a high severity vulnerability with a CVSS score of 7.8.
How can local users exploit CVE-2020-7331?
Local users can exploit CVE-2020-7331 by crafting and naming executable files in a specific way to cause a denial of service and execute malicious files.
Is there a fix available for CVE-2020-7331 in McAfee Endpoint Security?
Yes, a fix for CVE-2020-7331 is available in McAfee Endpoint Security 10.7.0 November 2020 Update.