Improperly implemented security check for standard in MVISION Endpoint Detection and Response (EDR) - CVE-2020-7327

 

Improperly implemented security check for standard in MVISION Endpoint Detection and Response (EDR) - CVE-2020-7327

Published: October 15, 2020 / Updated: October 19, 2020


Vulnerability identifier: #VU47715
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-7327
CWE-ID: CWE-358
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to bypass certain security restrictions.

The vulnerability exists due to improperly implemented security check. A local administrator can execute arbitrary code via stopping a core Windows service leaving McAfee core trust component in an inconsistent state resulting in MVISION EDR failing open rather than closed.


Affected software

MVISION Endpoint Detection and Response (EDR)

How to mitigate CVE-2020-7327

Install updates from vendor's website.

MVISION Endpoint Detection and Response (EDR) - update to 3.2.0.567

External References

Related Security Bulletins