Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-23879

Опубликовано: 15 мар. 2021
Источник: nvd
CVSS3: 6.7
CVSS2: 7.2
EPSS Низкий

Описание

Unquoted service path vulnerability in McAfee Endpoint Product Removal (EPR) Tool prior to 21.2 allows local administrators to execute arbitrary code, with higher-level privileges, via execution from a compromised folder. The tool did not enforce and protect the execution path. Local admin privileges are required to place the files in the required location.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mcafee:endpoint_product_removal_tool:*:*:*:*:*:*:*:*
Версия до 21.2 (исключая)

EPSS

Процентиль: 18%
0.00056
Низкий

6.7 Medium

CVSS3

7.2 High

CVSS2

Дефекты

CWE-428
CWE-428

Связанные уязвимости

CVSS3: 6.7
github
больше 3 лет назад

Unquoted service path vulnerability in McAfee Endpoint Product Removal (EPR) Tool prior to 21.2 allows local administrators to execute arbitrary code, with higher-level privileges, via execution from a compromised folder. The tool did not enforce and protect the execution path. Local admin privileges are required to place the files in the required location.

EPSS

Процентиль: 18%
0.00056
Низкий

6.7 Medium

CVSS3

7.2 High

CVSS2

Дефекты

CWE-428
CWE-428