First published: Fri Sep 17 2021(Updated: )
Improper privileges management vulnerability in McAfee Endpoint Security (ENS) Windows prior to 10.7.0 September 2021 Update allows local users to access files which they would otherwise not have access to via manipulating junction links to redirect McAfee folder operations to an unintended location.
Credit: psirt@mcafee.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mcafee Endpoint Security | <10.7.0 | |
Mcafee Endpoint Security | =10.7.0 | |
Mcafee Endpoint Security | =10.7.0-april_2020 | |
Mcafee Endpoint Security | =10.7.0-april_2021 | |
Mcafee Endpoint Security | =10.7.0-february_2020 | |
Mcafee Endpoint Security | =10.7.0-february_2021 | |
Mcafee Endpoint Security | =10.7.0-july_2020 | |
Mcafee Endpoint Security | =10.7.0-june_2021 | |
Mcafee Endpoint Security | =10.7.0-november_2020 | |
Mcafee Endpoint Security | =10.7.0-september_2020 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-31843 is an improper privileges management vulnerability in McAfee Endpoint Security (ENS) Windows prior to version 10.7.0.
CVE-2021-31843 allows local users to access files which they would otherwise not have access to via manipulating junction links to redirect McAfee folder operations to an unintended location.
CVE-2021-31843 has a severity rating of 7.8 (high).
CVE-2021-31843 affects McAfee Endpoint Security Windows versions prior to 10.7.0.
To fix CVE-2021-31843, update McAfee Endpoint Security Windows to version 10.7.0 or later.