CVE-2020-7274

EUVD-2020-28401
Privilege escalation vulnerability in McTray.exe in McAfee Endpoint Security (ENS) for Windows Prior to 10.7.0 April 2020 Update allows local users to spawn unrelated processes with elevated privileges via the system administrator granting McTray.exe elevated privileges (by default it runs with the current user's privileges).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.6 MEDIUM
LOCAL
HIGH
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:L
trellixCNA
6.6 MEDIUM
LOCAL
HIGH
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 29%
Affected Products (NVD)
VendorProductVersion
mcafeeendpoint_security
10.5.0
mcafeeendpoint_security
10.5.1
mcafeeendpoint_security
10.5.2
mcafeeendpoint_security
10.5.3
mcafeeendpoint_security
10.5.4
mcafeeendpoint_security
10.5.5
mcafeeendpoint_security
10.6.0
𝑥
= Vulnerable software versions