CVE Published: 21/08/2020 |
CVE Updated: 04/08/2024 |
CVE Year: 2020 Source: trellix |
Vendor: McAfee,LLC |
Product: McAfee Total Protection (MTP) Trial Status : PUBLISHED
CVE-2020-7310 Description
Privilege Escalation vulnerability in the installer in McAfee McAfee Total Protection (MTP) trial prior to 4.0.161.1 allows local users to change files that are part of write protection rules via manipulating symbolic links to redirect a McAfee file operations to an unintended file.
Metrics
CVSS Version: 3.1 |
Base Score: 6.9 MEDIUM Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:N/I:H/A:H
l➤ Exploitability Metrics: Attack Vector (AV)* LOCAL Attack Complexity (AC)* HIGH Privileges Required (PR)* HIGH User Interaction (UI)* REQUIRED Scope (S)* CHANGED
l➤ Impact Metrics: Confidentiality Impact (C)* NONE Integrity Impact (I)* HIGH Availability Impact (A)* HIGH