CVE-2020-7252

Severity CVSS v4.0:
Pending analysis
Type:
CWE-428 Unquoted Search Path or Element
Publication date:
17/02/2020
Last modified:
07/11/2023

Description

Unquoted service executable path in DXL Broker in McAfee Data eXchange Layer (DXL) Framework 6.0.0 and earlier allows local users to cause a denial of service and malicious file execution via carefully crafted and named executable files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mcafee:data_exchange_layer:*:*:*:*:*:*:*:* 6.0.0 (including)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools