CVE-2020-7337

MEDIUM

Mcafee Virusscan Enterprise < 8.8 - Incorrect Permission Assignment

Title source: rule
STIX 2.1

Description

Incorrect Permission Assignment for Critical Resource vulnerability in McAfee VirusScan Enterprise (VSE) prior to 8.8 Patch 16 allows local administrators to bypass local security protection through VSE not correctly integrating with Windows Defender Application Control via careful manipulation of the Code Integrity checks.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0003
EPSS Percentile 9.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-732
Status published
Products (2)
mcafee/virusscan_enterprise 8.8 (16 CPE variants)
mcafee/virusscan_enterprise < 8.8
Published Dec 09, 2020
Tracked Since Feb 18, 2026