CVE-2020-7314

HIGH

McAfee Agent for Mac < 5.6.6 - Privilege Escalation via Incorrect Temporary File Permissions

Title source: llm
STIX 2.1

Description

Privilege Escalation Vulnerability in the installer in McAfee Data Exchange Layer (DXL) Client for Mac shipped with McAfee Agent (MA) for Mac prior to MA 5.6.6 allows local users to run commands as root via incorrectly applied permissions on temporary files.

References (1)

Core 1
Core References

Scores

CVSS v3 8.2
EPSS 0.0036
EPSS Percentile 27.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Details

CWE
CWE-732
Status published
Products (1)
mcafee/mcafee_agent < 5.6.6
Published Sep 10, 2020
Tracked Since Feb 18, 2026