CVE-2020-7346: falha de alta gravidade em McAfee Data Loss Prevention (DLP) Endpoint for…
Privilege escalation in McAfee DLP Endpoint for Windows
Publicada em · Atualizada em
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 7.8epss 0.4%
probabilidade de exploração
0.4%top 73% das CVEs
exploração observada
nãonenhuma fonte reporta
Privilege Escalation vulnerability in McAfee Data Loss Prevention (DLP) for Windows prior to 11.6.100 allows a local, low privileged, attacker through the use of junctions to cause the product to load DLLs of the attacker's choosing. This requires the creation and removal of junctions by the attacker along with sending a specific IOTL command at the correct time.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
McAfee,LLC · McAfee Data Loss Prevention (DLP) Endpoint for WindowsCVEs relacionadas — McAfee Data Loss Prevention (DLP) Endpoint for…
No mesmo produto, das mais perigosas para as menos.
CVE-2021-31832MEDIUMCross site scripting vulnerability in DLP Endpoint for WindowsEPSS 0.5%CVE-2021-31844HIGHLocal Privilege Escalation in McAfee DLP Endpoint for WindowsEPSS 0.4%CVE-2021-23887HIGHPrivilege escalation in McAfee DLP Endpoint for WindowsEPSS 0.2%CVE-2021-23886MEDIUMLocal Denial of Service in McAfee DLP Endpoint for WindowsEPSS 0.2%