CVE-2020-7337: Incorrect Permission Assignment for Critical Resource
Incorrect Permission Assignment for Critical Resource vulnerability in McAfee VirusScan Enterprise (VSE) prior to 8.8 Patch 16 allows local administrators to bypass local security protection through VSE not correctly integrating with Windows Defender Application Control via careful manipulation of the Code Integrity checks.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this McAfee VirusScan Enterprise vulnerability?
The vulnerability ID for this McAfee VirusScan Enterprise vulnerability is CVE-2020-7337.
What is the severity level of CVE-2020-7337?
CVE-2020-7337 has a severity level of medium.
Which version of McAfee VirusScan Enterprise is affected by CVE-2020-7337?
McAfee VirusScan Enterprise versions prior to 8.8 Patch 16 are affected by CVE-2020-7337.
How can local administrators bypass security protection with CVE-2020-7337?
Local administrators can bypass security protection by carefully manipulating McAfee VirusScan Enterprise to not correctly integrate with Windows Defender Application Control.
Where can I find more information about CVE-2020-7337?
You can find more information about CVE-2020-7337 on the McAfee Knowledge Center website.