CVE-2020-7346 Vulnerability Details

  /     /     /  

CVE-2020-7346 Metadata Quick Info

CVE Published: 23/03/2021 | CVE Updated: 04/08/2024 | CVE Year: 2020
Source: trellix | Vendor: McAfee,LLC | Product: McAfee Data Loss Prevention (DLP) Endpoint for Windows
Status : PUBLISHED

CVE-2020-7346 Description

Privilege Escalation vulnerability in McAfee Data Loss Prevention (DLP) for Windows prior to 11.6.100 allows a local, low privileged, attacker through the use of junctions to cause the product to load DLLs of the attacker\'s choosing. This requires the creation and removal of junctions by the attacker along with sending a specific IOTL command at the correct time.

Metrics

CVSS Version: 3.1 | Base Score: 7.8 HIGH
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

l➤ Exploitability Metrics:
    Attack Vector (AV)* LOCAL
    Attack Complexity (AC)* LOW
    Privileges Required (PR)* LOW
    User Interaction (UI)* NONE
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* HIGH
    Integrity Impact (I)* HIGH
    Availability Impact (A)* HIGH

Weakness Enumeration (CWE)

CWE-ID: CWE-59
CWE Name: CWE-59: Improper Link Resolution Before File Access ( Link Following )
Source: McAfee,LLC

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).