Back to Database
Status published
Medium
CVE-2020-7259
Unsigned executable vulnerability in ENS can be used to bypass intended self-protection rules
Vulnerability Description
Exploitation of Privilege/Trust vulnerability in file in McAfee Endpoint Security (ENS) Prior to 10.7.0 February 2020 Update allows local users to bypass local security protection via a carefully crafted input file
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-7259
Credits & Attribution
No credits recorded in the NVD database.
More from McAfee LLC
View All →CVE-2021-23883
Null Pointer Dereference vulnerability in McAfee Endpoint Security (ENS)
Medium
4
CVE-2021-23882
Improper Access Control in the ENS installer
High
8.2
CVE-2021-23881
Stored Cross Site Scripting in ENS
Medium
4.8
CVE-2021-23880
Improper Access Control in the ENS installer
Medium
6.7
CVE-2021-23878
Clear text storage of sensitive Information in ENS
High
7.3
Affected Vendor
McAfee LLC
View all reports →Affected Software
McAfee Endpoint Security (ENS)
Vulnerable Versions:
10.x
Timeline
Official Publish:
April 15th, 2020
Last Modified:
September 17th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L