Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-7334

Опубликовано: 15 окт. 2020
Источник: nvd
CVSS3: 7.7
CVSS3: 8.2
CVSS2: 4.6
EPSS Низкий

Описание

Improper privilege assignment vulnerability in the installer McAfee Application and Change Control (MACC) prior to 8.3.2 allows local administrators to change or update the configuration settings via a carefully constructed MSI configured to mimic the genuine installer. This version adds further controls for installation/uninstallation of software.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mcafee:application_and_change_control:*:*:*:*:*:*:*:*
Версия до 8.3.2 (исключая)

EPSS

Процентиль: 16%
0.00051
Низкий

7.7 High

CVSS3

8.2 High

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-266
CWE-269

Связанные уязвимости

github
больше 3 лет назад

Improper privilege assignment vulnerability in the installer McAfee Application and Change Control (MACC) prior to 8.3.2 allows local administrators to change or update the configuration settings via a carefully constructed MSI configured to mimic the genuine installer. This version adds further controls for installation/uninstallation of software.

EPSS

Процентиль: 16%
0.00051
Низкий

7.7 High

CVSS3

8.2 High

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-266
CWE-269