CVE-2020-7323

Published at:
2020-09-09T10:15:11.633

Global infos:

Authentication Protection Bypass vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows physical local users to bypass the Windows lock screen via triggering certain detection events while the computer screen is locked and the McTray.exe is running with elevated privileges. This issue is timing dependent and requires physical access to the machine.

CVE Status: Modified

References:

  • [email protected]
  • af854a3a-2127-422b-91ae-364da2661108
  • Metrics:

    AttributeValue
    Attack ComplexityHIGH
    Attack VectorPHYSICAL
    Availability ImpactLOW
    Base Score6.9
    Base SeverityMEDIUM
    Confidentiality ImpactHIGH
    Integrity ImpactHIGH
    Privileges RequiredNONE
    ScopeCHANGED
    User InteractionREQUIRED
    Vector StringCVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L
    Exploitability Score0.4
    Impact Score6
    Source[email protected]
    TypeSecondary

    Links:

    Exploit-db
    Github