CVE-2020-7314
HIGHMcAfee Agent for Mac < 5.6.6 - Privilege Escalation via Incorrect Temporary File Permissions
Title source: llmDescription
Privilege Escalation Vulnerability in the installer in McAfee Data Exchange Layer (DXL) Client for Mac shipped with McAfee Agent (MA) for Mac prior to MA 5.6.6 allows local users to run commands as root via incorrectly applied permissions on temporary files.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_confirm
https://kc.mcafee.com/corporate/index?page=content&id=SB10325
Scores
CVSS v3
8.2
EPSS
0.0036
EPSS Percentile
27.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Details
CWE
CWE-732
Status
published
Products (1)
mcafee/mcafee_agent
< 5.6.6
Published
Sep 10, 2020
Tracked Since
Feb 18, 2026