CVE-2020-7346: high-severity vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for…
Privilege escalation in McAfee DLP Endpoint for Windows
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.8epss 0.4%
exploitation probability
0.4%top 73% of all CVEs
observed exploitation
nono source reports it
Privilege Escalation vulnerability in McAfee Data Loss Prevention (DLP) for Windows prior to 11.6.100 allows a local, low privileged, attacker through the use of junctions to cause the product to load DLLs of the attacker's choosing. This requires the creation and removal of junctions by the attacker along with sending a specific IOTL command at the correct time.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
McAfee,LLC · McAfee Data Loss Prevention (DLP) Endpoint for WindowsRelated CVEs — McAfee Data Loss Prevention (DLP) Endpoint for…
In the same product, most dangerous first.
CVE-2021-31832MEDIUMCross site scripting vulnerability in DLP Endpoint for WindowsEPSS 0.5%CVE-2021-31844HIGHLocal Privilege Escalation in McAfee DLP Endpoint for WindowsEPSS 0.4%CVE-2021-23887HIGHPrivilege escalation in McAfee DLP Endpoint for WindowsEPSS 0.2%CVE-2021-23886MEDIUMLocal Denial of Service in McAfee DLP Endpoint for WindowsEPSS 0.2%