CVE-2020-7337

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/12/2020
Last modified:
07/11/2023

Description

Incorrect Permission Assignment for Critical Resource vulnerability in McAfee VirusScan Enterprise (VSE) prior to 8.8 Patch 16 allows local administrators to bypass local security protection through VSE not correctly integrating with Windows Defender Application Control via careful manipulation of the Code Integrity checks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mcafee:virusscan_enterprise:*:*:*:*:*:*:*:* 8.8 (excluding)
cpe:2.3:a:mcafee:virusscan_enterprise:8.8:-:*:*:*:*:*:*
cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch1:*:*:*:*:*:*
cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch10:*:*:*:*:*:*
cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch11:*:*:*:*:*:*
cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch12:*:*:*:*:*:*
cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch13:*:*:*:*:*:*
cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch14:*:*:*:*:*:*
cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch15:*:*:*:*:*:*
cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch2:*:*:*:*:*:*
cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch3:*:*:*:*:*:*
cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch4:*:*:*:*:*:*
cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch5:*:*:*:*:*:*
cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch6:*:*:*:*:*:*
cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch7:*:*:*:*:*:*


References to Advisories, Solutions, and Tools