CVE-2020-7312

Severity CVSS v4.0:
Pending analysis
Type:
CWE-427 Uncontrolled Search Path Element
Publication date:
10/09/2020
Last modified:
07/11/2023

Description

DLL Search Order Hijacking Vulnerability in the installer in McAfee Agent (MA) for Windows prior to 5.6.6 allows local users to execute arbitrary code and escalate privileges via execution from a compromised folder.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mcafee:mcafee_agent:*:*:*:*:*:windows:*:* 5.6.6 (excluding)


References to Advisories, Solutions, and Tools