← back
CVE-2020-7276

Unrestricted Policy Management using MfeUpgradeTool.exe

CVSS 6.4 MEDIUMEPSS 0.3%CWE-287
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.4EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
15 Apr 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Authentication bypass vulnerability in MfeUpgradeTool in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 April 2020 Update allows administrator users to access policy settings via running this tool.
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:H/A:L

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →