CVE-2020-7263
Last modified
CVE-2020-7263 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. Improper access control vulnerability in ESconfigTool.exe in McAfee Endpoint Security (ENS) for Windows all current versions allows local administrator to alter ENS configuration up to and including disabling all protection offered by ENS via insecurely implemented encryption of configuration for export and import.. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
Improper access control vulnerability in ESconfigTool.exe in McAfee Endpoint Security (ENS) for Windows all current versions allows local administrator to alter ENS configuration up to and including disabling all protection offered by ENS via insecurely implemented encryption of configuration for export and import.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mcafee | Endpoint Security | 10.5.0 |
| Mcafee | Endpoint Security | 10.5.1 |
| Mcafee | Endpoint Security | 10.5.2 |
| Mcafee | Endpoint Security | 10.5.3 |
| Mcafee | Endpoint Security | 10.5.4 |
| Mcafee | Endpoint Security | 10.5.5 |
| Mcafee | Endpoint Security | 10.6.0 |
| Mcafee | Endpoint Security | 10.6.1 |
| Mcafee | Endpoint Security | 10.7.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-7263?
How severe is CVE-2020-7263?
How do I fix CVE-2020-7263?
Are you affected by CVE-2020-7263?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
