Privilege Escalation through Symbolic Link Manipulation in McAfee Virus Scan Enterprise (VSE) prior to 8.8 Patch 15

Privilege Escalation through Symbolic Link Manipulation in McAfee Virus Scan Enterprise (VSE) prior to 8.8 Patch 15

CVE-2020-7280 · HIGH Severity

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Privilege Escalation vulnerability during daily DAT updates when using McAfee Virus Scan Enterprise (VSE) prior to 8.8 Patch 15 allows local users to cause the deletion and creation of files they would not normally have permission to through altering the target of symbolic links. This is timing dependent.

Learn more about our User Device Pen Test.