Rapid7 Vulnerability & Exploit Database

McAfee Endpoint Security Platform: CVE-2019-3652: Endpoint security for windows update fixes three vulnerabilities (SB10299)

Free InsightVM Trial No Credit Card Necessary
Watch Demo See how it all works
Back to Search

McAfee Endpoint Security Platform: CVE-2019-3652: Endpoint security for windows update fixes three vulnerabilities (SB10299)

Severity
5
CVSS
(AV:L/AC:L/Au:N/C:P/I:P/A:P)
Published
10/09/2019
Created
08/12/2020
Added
08/11/2020
Modified
03/10/2022

Description

Code Injection vulnerability in EPSetup.exe in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 2019 Update allows local user to get their malicious code installed by the ENS installer via code injection into EPSetup.exe by an attacker with access to the installer.

Solution(s)

  • mcafee-endpoint-security-platform-upgrade-10-5-5-5329
  • mcafee-endpoint-security-platform-upgrade-10-6-1-1872
  • mcafee-endpoint-security-platform-upgrade-10-7-0-1481

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;