Vulnerability Description
Privilege Escalation vulnerability in Microsoft Windows client McAfee Total Protection (MTP) prior to 16.0.29 allows local users to gain elevated privileges via careful manipulation of a folder by creating a junction link. This exploits a lack of protection through a timing issue and is only exploitable in a small time window.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mcafee | Total Protection | < 16.0.29 |
Related Weaknesses (CWE)
References
- http://service.mcafee.com/FAQDocument.aspx?&id=TS103089
- https://www.zerodayinitiative.com/advisories/ZDI-20-1388/
- http://service.mcafee.com/FAQDocument.aspx?&id=TS103089
- https://www.zerodayinitiative.com/advisories/ZDI-20-1388/
FAQ
What is CVE-2020-7335?
CVE-2020-7335 is a vulnerability with a CVSS score of 7.5 (HIGH). Privilege Escalation vulnerability in Microsoft Windows client McAfee Total Protection (MTP) prior to 16.0.29 allows local users to gain elevated privileges via careful manipulation of a folder by cre...
How severe is CVE-2020-7335?
CVE-2020-7335 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-7335?
Check the references section above for vendor advisories and patch information. Affected products include: Mcafee Total Protection.