CVE-2020-7283
03.07.2020, 14:15
Privilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to create and edit files via symbolic link manipulation in a location they would otherwise not have access to. This is achieved through running a malicious script or program on the target machine.Enginsight
Vendor | Product | Version |
---|---|---|
mcafee | total_protection | 𝑥 < 16.0.r26 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-274 - Improper Handling of Insufficient PrivilegesThe software does not handle or incorrectly handles when it has insufficient privileges to perform an operation, leading to resultant weaknesses.
- CWE-269 - Improper Privilege ManagementThe software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.