CVE-2020-7334

HIGH

McAfee Application and Change Control < 8.3.2 - Improper Privilege Assignment via MSI Installer

Title source: llm
STIX 2.1

Description

Improper privilege assignment vulnerability in the installer McAfee Application and Change Control (MACC) prior to 8.3.2 allows local administrators to change or update the configuration settings via a carefully constructed MSI configured to mimic the genuine installer. This version adds further controls for installation/uninstallation of software.

References (1)

Core 1
Core References

Scores

CVSS v3 7.7
EPSS 0.0005
EPSS Percentile 16.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

Details

CWE
CWE-269 CWE-266
Status published
Products (1)
mcafee/application_and_change_control < 8.3.2
Published Oct 15, 2020
Tracked Since Feb 18, 2026