#VU46684 Permissions, Privileges, and Access Controls in McAfee Agent - CVE-2020-7314
Published: September 14, 2020
Vulnerability identifier: #VU46684
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-7314
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
McAfee Agent
McAfee Agent
Software vendor:
McAfee
McAfee
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions in the installer in McAfee Data Exchange Layer (DXL) Client for Mac shipped with McAfee Agent (MA) for Mac, which leads to security restrictions bypass and privilege escalation.
Remediation
Install updates from vendor's website.