First published: Wed Feb 10 2021(Updated: )
Improper Access Control in attribute in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update allows authenticated local administrator user to perform an uninstallation of the anti-malware engine via the running of a specific command with the correct parameters.
Credit: psirt@mcafee.com trellixpsirt@trellix.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mcafee Endpoint Security | <10.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23880 is a vulnerability that allows an authenticated local administrator user to uninstall the anti-malware engine in McAfee Endpoint Security (ENS) for Windows prior to version 10.7.0.
CVE-2021-23880 allows an authenticated local administrator user to uninstall the anti-malware engine in McAfee Endpoint Security.
CVE-2021-23880 has a severity rating of medium, with a CVSS score of 4.4.
To fix CVE-2021-23880, update McAfee Endpoint Security to version 10.7.0 or later.
More information about CVE-2021-23880 can be found at the following link: [McAfee Security Bulletin SB10345](https://kc.mcafee.com/corporate/index?page=content&id=SB10345)