CVE-2020-7346

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
23/03/2021
Last modified:
07/11/2023

Description

Privilege Escalation vulnerability in McAfee Data Loss Prevention (DLP) for Windows prior to 11.6.100 allows a local, low privileged, attacker through the use of junctions to cause the product to load DLLs of the attacker&amp;#39;s choosing. This requires the creation and removal of junctions by the attacker along with sending a specific IOTL command at the correct time.<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mcafee:data_loss_prevention:*:*:*:*:*:windows:*:* 11.6.100 (excluding)


References to Advisories, Solutions, and Tools