CVE-2020-7346
Last modified
CVE-2020-7346 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Privilege Escalation vulnerability in McAfee Data Loss Prevention (DLP) for Windows prior to 11.6.100 allows a local, low privileged, attacker through the use of junctions to cause the product to load DLLs of the attacker's choosing. This requires the creation and removal of junctions by the attacker along with sending a specific IOTL command at the correct time.. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
Privilege Escalation vulnerability in McAfee Data Loss Prevention (DLP) for Windows prior to 11.6.100 allows a local, low privileged, attacker through the use of junctions to cause the product to load DLLs of the attacker's choosing. This requires the creation and removal of junctions by the attacker along with sending a specific IOTL command at the correct time.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mcafee | Data Loss Prevention | < 11.6.100 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-7346?
How severe is CVE-2020-7346?
How do I fix CVE-2020-7346?
Are you affected by CVE-2020-7346?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
