Improper Authentication in McAfee Endpoint Security (ENS) - CVE-2020-7323

 

Improper Authentication in McAfee Endpoint Security (ENS) - CVE-2020-7323

Published: September 14, 2020


Vulnerability identifier: #VU46690
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-7323
CWE-ID: CWE-287
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to bypass authentication process.

The vulnerability exists due to an error in when processing authentication requests. An attacker with physical access can bypass the Windows lock screen via triggering certain detection events while the computer screen is locked and the McTray.exe is running with elevated privileges.

Note: This vulnerability affects the following versions:

  • 10.7.0.x
  • 10.6.x
  • 10.5.x

Affected software

McAfee Endpoint Security (ENS)

How to mitigate CVE-2020-7323

Install updates from vendor's website.

McAfee Endpoint Security (ENS) - addressed in versions 10.6.1 September 2020 Update, 10.7.0 September 2020 Update

External References

Related Security Bulletins