CVE-2020-7261

MEDIUM

Mcafee Endpoint Security - Memory Corruption

Title source: rule
STIX 2.1

Description

Buffer Overflow via Environment Variables vulnerability in AMSI component in McAfee Endpoint Security (ENS) Prior to 10.7.0 February 2020 Update allows local users to disable Endpoint Security via a carefully crafted user input.

References (1)

Core 1
Core References

Scores

CVSS v3 6.1
EPSS 0.0013
EPSS Percentile 31.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:N

Details

CWE
CWE-119 CWE-120
Status published
Products (7)
mcafee/endpoint_security 10.5.0
mcafee/endpoint_security 10.5.1
mcafee/endpoint_security 10.5.2
mcafee/endpoint_security 10.5.3
mcafee/endpoint_security 10.5.4
mcafee/endpoint_security 10.5.5
mcafee/endpoint_security 10.6.0
Published Apr 15, 2020
Tracked Since Feb 18, 2026