Vulnerability CVE-2020-7323


Published: 2020-09-09

Description:
Authentication Protection Bypass vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows physical local users to bypass the Windows lock screen via triggering certain detection events while the computer screen is locked and the McTray.exe is running with elevated privileges. This issue is timing dependent and requires physical access to the machine.

Type:

CWE-287

(Improper Authentication)

CVSS2 => (AV:L/AC:H/Au:N/C:C/I:C/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5.9/10
9.5/10
1.9/10
Exploit range
Attack complexity
Authentication
Local
High
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Partial
Affected software
Mcafee -> Endpoint security 

 References:
https://kc.mcafee.com/corporate/index?page=content&id=SB10327

Copyright 2024, cxsecurity.com

 

Back to Top