CVE-2021-23882: Improper Access Control in the ENS installer
Improper Access Control vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update allows local administrators to prevent the installation of some ENS files by placing carefully crafted files where ENS will be installed. This is only applicable to clean installations of ENS as the Access Control rules will prevent modification prior to up an upgrade.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this McAfee Endpoint Security vulnerability?
The vulnerability ID for this McAfee Endpoint Security vulnerability is CVE-2021-23882.
What is the severity level of CVE-2021-23882?
The severity level of CVE-2021-23882 is high with a severity value of 4.4.
What is the description of CVE-2021-23882?
CVE-2021-23882 is an Improper Access Control vulnerability in McAfee Endpoint Security (ENS) for Windows prior to version 10.7.0.
Which version of McAfee Endpoint Security is affected by this vulnerability?
This vulnerability affects McAfee Endpoint Security for Windows versions prior to 10.7.0.
How can local administrators exploit this vulnerability?
Local administrators can prevent the installation of some ENS files by placing carefully crafted files where ENS will be installed.