Authentication Protection Bypass vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows physical local users to bypass the Windows lock screen via triggering certain detection events while the computer screen is locked and the McTray.exe is running with elevated privileges. This issue is timing dependent and requires physical access to the machine.
CVSS Details
- CVSS 3.1 Base Score: 6.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Mcafee Endpoint Security Platform | — | Update McAfee Endpoint Security Platform to version 10.6.1.2113Update McAfee Endpoint Security Platform to version 10.7.0.2000 | Oct 20, 2020 | Sep 9, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub