CVE-2020-7335

HIGH

McAfee Total Protection < 16.0.29 - Privilege Escalation via Junction Link Timing Attack

Title source: llm
STIX 2.1

Description

Privilege Escalation vulnerability in Microsoft Windows client McAfee Total Protection (MTP) prior to 16.0.29 allows local users to gain elevated privileges via careful manipulation of a folder by creating a junction link. This exploits a lack of protection through a timing issue and is only exploitable in a small time window.

References (2)

Core 2
Core References
Various Sources x_refsource_confirm
http://service.mcafee.com/FAQDocument.aspx?&id=TS103089
Third Party Advisory x_refsource_misc
https://www.zerodayinitiative.com/advisories/ZDI-20-1388/

Scores

CVSS v3 7.5
EPSS 0.0011
EPSS Percentile 29.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

Details

CWE
CWE-269
Status published
Products (1)
mcafee/total_protection < 16.0.29
Published Dec 01, 2020
Tracked Since Feb 18, 2026