CVE-2020-7250
Summary
| CVE | CVE-2020-7250 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-15 13:15:00 UTC |
| Updated | 2023-11-07 03:25:00 UTC |
| Description | Symbolic link manipulation vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2020 Update allows authenticated local user to potentially gain an escalation of privileges by pointing the link to files which the user which not normally have permission to alter via carefully creating symbolic links from the ENS log file directory. |
Risk And Classification
Problem Types: CWE-59
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mcafee | Endpoint Security | 10.5.0 | All | All | All |
| Application | Mcafee | Endpoint Security | 10.5.1 | All | All | All |
| Application | Mcafee | Endpoint Security | 10.5.2 | All | All | All |
| Application | Mcafee | Endpoint Security | 10.5.3 | All | All | All |
| Application | Mcafee | Endpoint Security | 10.5.4 | All | All | All |
| Application | Mcafee | Endpoint Security | 10.5.5 | All | All | All |
| Application | Mcafee | Endpoint Security | 10.6.0 | All | All | All |
| Application | Mcafee | Endpoint Security | 10.5.0 | All | All | All |
| Application | Mcafee | Endpoint Security | 10.5.1 | All | All | All |
| Application | Mcafee | Endpoint Security | 10.5.2 | All | All | All |
| Application | Mcafee | Endpoint Security | 10.5.3 | All | All | All |
| Application | Mcafee | Endpoint Security | 10.5.4 | All | All | All |
| Application | Mcafee | Endpoint Security | 10.5.5 | All | All | All |
| Application | Mcafee | Endpoint Security | 10.6.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| McAfee Security Bulletin - Endpoint Security for Windows update fixes multiple vulnerabilities (CVE-2020-7250, CVE-2020-7255, CVE-2020-7257, CVE-2020-7259, CVE-2020-7261, CVE-2020-7273, CVE-2020-7274, CVE-2020-7275, CVE-2020-7276, CVE-2020-7277, CVE-2020-7278) | CONFIRM | kc.mcafee.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: McAfee credits Jakub Palaczynski (ING Tech Poland) and Eran Shimony (CyberArk) for independently reporting this flaw
There are currently no legacy QID mappings associated with this CVE.