CVE-2019-3652
Last modified
CVE-2019-3652 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Code Injection vulnerability in EPSetup.exe in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 2019 Update allows local user to get their malicious code installed by the ENS installer via code injection into EPSetup.exe by an attacker with access to the installer.. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
Code Injection vulnerability in EPSetup.exe in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 2019 Update allows local user to get their malicious code installed by the ENS installer via code injection into EPSetup.exe by an attacker with access to the installer.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mcafee | Endpoint Security | >= 10.5.0, <= 10.5.5 |
| Mcafee | Endpoint Security | >= 10.6.0, < 10.6.1 |
| Mcafee | Endpoint Security | 10.6.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-3652?
How severe is CVE-2019-3652?
How do I fix CVE-2019-3652?
Are you affected by CVE-2019-3652?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
