
Cloud Vulnerability DB
A community-led vulnerabilities database
A privilege escalation vulnerability was identified in McAfee Virus Scan Enterprise (VSE) versions prior to 8.8 Patch 15, tracked as CVE-2020-7280. The vulnerability was discovered on December 27, 2019, and publicly disclosed on June 15, 2020. The flaw specifically affects the daily DAT update process and allows local users to manipulate file permissions through symbolic link manipulation (ZDI Advisory).
The vulnerability exists within the processing of log files during daily DAT updates. The flaw allows local attackers to exploit timing-dependent conditions by creating a junction that can be used to abuse the product to overwrite the contents of chosen files. The vulnerability has been assigned a CVSS score of 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), indicating high severity with local access requirements (ZDI Advisory).
Successful exploitation of this vulnerability allows attackers to escalate privileges and execute code in the context of SYSTEM, effectively gaining complete control over the affected system. This enables attackers to perform unauthorized file operations, including deletion and creation of files that would normally be restricted (ZDI Advisory).
The vulnerability requires an attacker to first obtain the ability to execute low-privileged code on the target system. The exploitation is timing-dependent and involves manipulating symbolic links during the DAT update process (ZDI Advisory).
McAfee has released a security update to address this vulnerability. Users are advised to upgrade to VSE 8.8 Patch 15 or later versions to mitigate this security issue (McAfee Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."